|
219011
|
5.4 |
MEDIUM
Adjacent
|
huawei
|
myna_firmware
|
There is an information leak vulnerability in Huawei smart speaker Myna. When the smart speaker is paired with the cloud through Wi-Fi, the speaker incorrectly processes some data. Attackers can expl…
|
NVD-CWE-noinfo
|
CVE-2019-5271
|
2024-11-21 13:44 |
2019-11-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219012
|
5.5 |
MEDIUM
Local
|
huawei
|
atlas_300_firmware atlas_500_firmware
|
Huawei Atlas 300, Atlas 500 have a buffer overflow vulnerability. A local, authenticated attacker may craft specific parameter and send to the process to exploit this vulnerability. Successfully expl…
|
CWE-120
Classic Buffer Overflow
|
CVE-2019-5247
|
2024-11-21 13:44 |
2019-11-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219013
|
8.1 |
HIGH
Adjacent
|
huawei
|
cd10-10_firmware cd16-10_firmware cd17-10_firmware cd18-10_firmware hirouter-cd15-10_firmware hirouter-cd20-10_firmware hirouter-cd21-16_firmware hirouter-cd30-10_firmware hir…
|
Some Huawei home routers have an input validation vulnerability. Due to input parameter is not correctly verified, an attacker can exploit this vulnerability by sending special constructed packets to…
|
CWE-20
Improper Input Validation
|
CVE-2019-5268
|
2024-11-21 13:44 |
2019-11-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219014
|
7.8 |
HIGH
Local
|
huawei
|
cd10-10_firmware cd16-10_firmware cd17-10_firmware cd18-10_firmware hirouter-cd15-10_firmware hirouter-cd20-10_firmware hirouter-cd21-16_firmware hirouter-cd30-10_firmware hir…
|
Some Huawei home routers have an improper authorization vulnerability. Due to improper authorization of certain programs, an attacker can exploit this vulnerability to execute uploaded malicious file…
|
NVD-CWE-noinfo
|
CVE-2019-5269
|
2024-11-21 13:44 |
2019-11-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219015
|
5.5 |
MEDIUM
Local
|
huawei
|
hwbackup hisuite
|
HiSuite with 9.1.0.305 and earlier versions and 9.1.0.305(MAC) and earlier versions and HwBackup with earlier versions before 9.1.1.308 have a brute forcing encrypted backup data vulnerability. Huawe…
|
CWE-307
mproper Restriction of Excessive Authentication Attempts
|
CVE-2019-5263
|
2024-11-21 13:44 |
2019-11-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219016
|
7.5 |
HIGH
Network
|
huawei
|
vp9630_firmware vp9650_firmware vp9660_firmware
|
There is a use of insufficiently random values vulnerability in Huawei ViewPoint products. An unauthenticated, remote attacker can guess information by a large number of attempts. Successful exploita…
|
CWE-330
Use of Insufficiently Random Values
|
CVE-2019-5232
|
2024-11-21 13:44 |
2019-11-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219017
|
5.5 |
MEDIUM
Local
|
huawei
|
p30_firmware p30_pro_firmware mate_20_firmware hisuite_firmware
|
P30, P30 Pro, Mate 20 smartphones with software of versions earlier than ELLE-AL00B 9.1.0.193(C00E190R2P1), versions earlier than VOGUE-AL00A 9.1.0.193(C00E190R2P1), versions earlier than Hima-AL00B …
|
CWE-346
Origin Validation Error
|
CVE-2019-5227
|
2024-11-21 13:44 |
2019-11-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219018
|
5.5 |
MEDIUM
Local
|
huawei
|
p30_firmware
|
P30 smartphones with versions earlier than ELLE-AL00B 9.1.0.193(C00E190R1P21) have an out of bounds read vulnerability. The system does not properly validate certain length parameter which an applica…
|
CWE-125
Out-of-bounds Read
|
CVE-2019-5224
|
2024-11-21 13:44 |
2019-11-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219019
|
8.8 |
HIGH
Adjacent
|
huawei
|
band_2_firmware band_3_firmware
|
There is an insufficient authentication vulnerability in Huawei Band 2 and Honor Band 3. The band does not sufficiently authenticate the device try to connect to it in certain scenario. Successful ex…
|
CWE-287
Improper Authentication
|
CVE-2019-5218
|
2024-11-21 13:44 |
2019-11-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219020
|
5.5 |
MEDIUM
Local
|
huawei
|
p20_firmware
|
There is an improper access control vulnerability in Huawei Share. The software does not properly restrict access to certain file from certain application. An attacker tricks the user into installing…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2019-5212
|
2024-11-21 13:44 |
2019-11-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|