CVE-2019-5271 is an information leak vulnerability affecting Huawei Myna smart speakers and their firmware. During Wi-Fi cloud pairing, the speaker improperly processes data, allowing an attacker on the adjacent network to read and modify specific speaker configurations. Rated as Medium severity (CVSS 5.4), this vulnerability requires adjacent network access and has low impact on confidentiality and integrity, with no impact on availability. There is no public exploit code available, no evidence of active exploitation, and minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
9.0.1.9\(h100sp6c00\)CPE matchmatch criteria | cpe:2.3:o:huawei:myna_firmware:9.0.1.9\(h100sp6c00\):*:*:*:*:*:*:* | ||
9.0.1.10\(h100sp5c00\)CPE matchmatch criteria | cpe:2.3:o:huawei:myna_firmware:9.0.1.10\(h100sp5c00\):*:*:*:*:*:*:* | ||
9.0.1.10\(h100sp8c00\)CPE matchmatch criteria | cpe:2.3:o:huawei:myna_firmware:9.0.1.10\(h100sp8c00\):*:*:*:*:*:*:* | ||
9.0.1.10\(h100sp10c00\)CPE matchmatch criteria | cpe:2.3:o:huawei:myna_firmware:9.0.1.10\(h100sp10c00\):*:*:*:*:*:*:* | ||
9.0.1.10\(h100sp11c00\)CPE matchmatch criteria | cpe:2.3:o:huawei:myna_firmware:9.0.1.10\(h100sp11c00\):*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.