Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Huawei Technologies

First CVE: Jan 25, 2007Active for: 19 yearsTotal CVEs: 2,346
43.9
VTI Score
High

Huawei Technologies operates one of the broadest vulnerability footprints in the landscape, spanning operating systems, mobile platforms, firmware, and enterprise networking equipment deployed across consumer, enterprise, and infrastructure segments globally. Vulnerabilities affecting the vendor skew toward serious outcomes, with a meaningful share reaching critical severity, though the exposure recurs across a diverse product portfolio including HarmonyOS, EMUI, MagicUI, and SecuSpace appliances rather than concentrating in a single tier. The recurring weakness classes center on input-validation deficiencies and memory-safety issues—improper input validation, out-of-bounds reads and writes, and buffer-boundary violations—that are characteristic of large, heterogeneous codebases spanning operating systems, middleware, and firmware stacks. Defenders should treat this vendor's advisories as broadly applicable given the scale and diversity of deployments and should prioritize appliance and firmware updates in their environments. Current exploitation activity and severity distributions are shown alongside this summary.

FAUCET AI Generated
2,346
Total CVEs
More Total CVEs than 100% of tracked vendors
0.1
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 1% of tracked vendors
6.8
Avg CVSS Score
Higher Avg CVSS Score than 44% of tracked vendors
0.1%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Huawei Technologies over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 25, 2007
19 years ago
Most Recent CVE
Apr 13, 2026
102 days ago

Self-Reporting Analysis

Of all the CVEs published by Huawei Technologies as a CNA, 98.1% affect products that Huawei Technologies develops as a vendor.

98.1%
Self-reported: 2,145 (98.1%)
Third-party: 42 (1.9%)

Of all the CVEs published that affect products developed by Huawei Technologies, 91.4% are self-published by Huawei Technologies as a CNA.

91.4%
Self-published: 2,145 (91.4%)
Other CNAs: 201 (8.6%)

Products(1,954 total)

Top CVEs

Signals from CVEs in this vendor scope (2346 CVEs).

2,346 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2019-0708CRITICAL
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unauthenticated attacker connects to the target system using RDP
May 16, 20199.899YESYES
CVE-2019-2215HIGH
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interaction is required to exploit this vulnerability, however exploi
Oct 11, 20197.896YESYES
CVE-2017-14491CRITICAL
Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted DNS response.
Oct 4, 20179.885NOYES
CVE-2017-17215HIGH
Huawei HG532 with some customized versions has a remote code execution vulnerability. An authenticated attacker could send malicious packets to port 37215 to launch attacks. Succes
Mar 20, 20188.884NOYES
CVE-2020-0069HIGH
In the ioctl handlers of the Mediatek Command Queue driver, there is a possible out of bounds write due to insufficient input sanitization and missing SELinux restrictions. This co
Mar 10, 20207.860YESNO
CVE-2015-2808LOW
The RC4 algorithm, as used in the TLS protocol and SSL protocol, does not properly combine state data with key data during the initialization phase, which makes it easier for remot
Apr 1, 20153.752NONO
CVE-2020-8840CRITICAL
FasterXML jackson-databind 2.0.0 through 2.9.10.2 lacks certain xbean-reflect/JNDI blocking, as demonstrated by org.apache.xbean.propertyeditor.JndiConverter.
Feb 10, 20209.845NONO
CVE-2018-7921MEDIUM
Huawei B315s-22 products with software of 21.318.01.00.26 have an information leak vulnerability. Unauthenticated adjacent attackers may exploit this vulnerability to obtain device
Sep 12, 20186.539NOYES
CVE-2015-7254MEDIUM
Directory traversal vulnerability on Huawei HG532e, HG532n, and HG532s devices allows remote attackers to read arbitrary files via a .. (dot dot) in an icon/ URI.
Nov 7, 20155.035NOYES
CVE-2016-8769MEDIUM
Huawei UTPS earlier than UTPS-V200R003B015D16SPC00C983 has an unquoted service path vulnerability which can lead to the truncation of UTPS service query paths. An attacker may put
Apr 2, 20176.733NOYES
View all 2,346 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products2,346 CVEs
40%
45%
9%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local740 (31.5%)
Network1,325 (56.5%)
Unknown52 (2.2%)
Physical110 (4.7%)
Adjacent Network119 (5.1%)
Attack Complexity
Low2,131 (90.8%)
High163 (6.9%)
Unknown52 (2.2%)
User Interaction
None2,007 (85.5%)
Unknown52 (2.2%)
Required287 (12.2%)
Privileges Required
Low576 (24.6%)
High102 (4.3%)
None1,616 (68.9%)
Unknown52 (2.2%)

Exploit Exposure

Signals from CVEs in this vendor scope (2346 CVEs).

CISA KEV
3 CVEs
0.1% of CVEs· 99th percentile
Metasploit
3 CVEs
0.1% of CVEs· 97th percentile
Nuclei
1 CVE
0.0% of CVEs· 95th percentile
ExploitDB
23 CVEs
1.0% of CVEs· 74th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Huawei Technologies.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Huawei Technologies — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Huawei Technologies's Products

View all 10 CNAs →

Top CWEs