Huawei Technologies operates one of the broadest vulnerability footprints in the landscape, spanning operating systems, mobile platforms, firmware, and enterprise networking equipment deployed across consumer, enterprise, and infrastructure segments globally. Vulnerabilities affecting the vendor skew toward serious outcomes, with a meaningful share reaching critical severity, though the exposure recurs across a diverse product portfolio including HarmonyOS, EMUI, MagicUI, and SecuSpace appliances rather than concentrating in a single tier. The recurring weakness classes center on input-validation deficiencies and memory-safety issues—improper input validation, out-of-bounds reads and writes, and buffer-boundary violations—that are characteristic of large, heterogeneous codebases spanning operating systems, middleware, and firmware stacks. Defenders should treat this vendor's advisories as broadly applicable given the scale and diversity of deployments and should prioritize appliance and firmware updates in their environments. Current exploitation activity and severity distributions are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Huawei Technologies over time
Of all the CVEs published by Huawei Technologies as a CNA, 98.1% affect products that Huawei Technologies develops as a vendor.
Of all the CVEs published that affect products developed by Huawei Technologies, 91.4% are self-published by Huawei Technologies as a CNA.
Signals from CVEs in this vendor scope (2346 CVEs).
2,346 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-0708CRITICAL A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unauthenticated attacker connects to the target system using RDP | May 16, 2019 | 9.8 | 99 | YES | YES |
CVE-2019-2215HIGH A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interaction is required to exploit this vulnerability, however exploi | Oct 11, 2019 | 7.8 | 96 | YES | YES |
CVE-2017-14491CRITICAL Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted DNS response. | Oct 4, 2017 | 9.8 | 85 | NO | YES |
CVE-2017-17215HIGH Huawei HG532 with some customized versions has a remote code execution vulnerability. An authenticated attacker could send malicious packets to port 37215 to launch attacks. Succes | Mar 20, 2018 | 8.8 | 84 | NO | YES |
CVE-2020-0069HIGH In the ioctl handlers of the Mediatek Command Queue driver, there is a possible out of bounds write due to insufficient input sanitization and missing SELinux restrictions. This co | Mar 10, 2020 | 7.8 | 60 | YES | NO |
The RC4 algorithm, as used in the TLS protocol and SSL protocol, does not properly combine state data with key data during the initialization phase, which makes it easier for remot | Apr 1, 2015 | 3.7 | 52 | NO | NO |
CVE-2020-8840CRITICAL FasterXML jackson-databind 2.0.0 through 2.9.10.2 lacks certain xbean-reflect/JNDI blocking, as demonstrated by org.apache.xbean.propertyeditor.JndiConverter. | Feb 10, 2020 | 9.8 | 45 | NO | NO |
CVE-2018-7921MEDIUM Huawei B315s-22 products with software of 21.318.01.00.26 have an information leak vulnerability. Unauthenticated adjacent attackers may exploit this vulnerability to obtain device | Sep 12, 2018 | 6.5 | 39 | NO | YES |
CVE-2015-7254MEDIUM Directory traversal vulnerability on Huawei HG532e, HG532n, and HG532s devices allows remote attackers to read arbitrary files via a .. (dot dot) in an icon/ URI. | Nov 7, 2015 | 5.0 | 35 | NO | YES |
CVE-2016-8769MEDIUM Huawei UTPS earlier than UTPS-V200R003B015D16SPC00C983 has an unquoted service path vulnerability which can lead to the truncation of UTPS service query paths. An attacker may put | Apr 2, 2017 | 6.7 | 33 | NO | YES |
Signals from CVEs in this vendor scope (2346 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Huawei Technologies.
Media articles that mention a CVE ID that affects a product developed by Huawei Technologies — matched by CVE ID, not by vendor name.