Huawei Harmonyos vulnerabilities
1,111 known vulnerabilities affecting huawei/harmonyos.
Total CVEs
1,111
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL138HIGH539MEDIUM394LOW40
Vulnerabilities
Page 37 of 56
CVE-2021-40003P4MEDIUMCVSS 5.3fixed in 2.0v2.02022-01-10
CVE-2021-40003 [MEDIUM] CWE-22 CVE-2021-40003: HwPCAssistant has a path traversal vulnerability. Successful exploitation of this vulnerability may
HwPCAssistant has a path traversal vulnerability. Successful exploitation of this vulnerability may affect data confidentiality.
nvd
CVE-2025-48910P4MEDIUMCVSS 5.5v4.3.0v5.0.02025-06-06
CVE-2025-48910 [MEDIUM] CWE-122 CVE-2025-48910: Buffer overflow vulnerability in the DFile module Impact: Successful exploitation of this vulnerabil
Buffer overflow vulnerability in the DFile module
Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2026-24928P4MEDIUMCVSS 5.5v4.2.02026-02-06
CVE-2026-24928 [MEDIUM] CWE-680 CVE-2026-24928: Out-of-bounds write vulnerability in the file system module. Impact: Successful exploitation of this
Out-of-bounds write vulnerability in the file system module.
Impact: Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2025-68959P4MEDIUMCVSS 5.5v3.0.0v3.1.0+4 more2026-01-14
CVE-2025-68959 [MEDIUM] CWE-200 CVE-2025-68959: Permission verification bypass vulnerability in the media library module. Impact: Successful exploit
Permission verification bypass vulnerability in the media library module.
Impact: Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2025-68970P4MEDIUMCVSS 5.5v3.0.0v3.1.0+4 more2026-01-14
CVE-2025-68970 [MEDIUM] CWE-20 CVE-2025-68970: Permission verification bypass vulnerability in the media library module. Impact: Successful exploit
Permission verification bypass vulnerability in the media library module.
Impact: Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2023-0117P4MEDIUMCVSS 5.3v3.1.0v3.0.02023-05-26
CVE-2023-0117 [MEDIUM] CWE-287 CVE-2023-0117: The online authentication provided by the hwKitAssistant lacks strict identity verification of appli
The online authentication provided by the hwKitAssistant lacks strict identity verification of applications. Successful exploitation of this vulnerability may affect availability of features,such as MeeTime.
nvd
CVE-2026-41972P4MEDIUMCVSS 5.4v6.1.0v6.0.0+1 more2026-06-09
CVE-2026-41972 [MEDIUM] CWE-22 CVE-2026-41972: Path traversal vulnerability in the SMS app. Impact: Successful exploitation of this vulnerability m
Path traversal vulnerability in the SMS app. Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2022-48491P4MEDIUMCVSS 5.3v3.1.0v3.0.0+2 more2023-06-19
CVE-2022-48491 [MEDIUM] CWE-862 CVE-2022-48491: Vulnerability of missing authentication on certain HUAWEI phones.Successful exploitation of this vul
Vulnerability of missing authentication on certain HUAWEI phones.Successful exploitation of this vulnerability can lead to ads and other windows to display at any time.
nvd
CVE-2023-34165P4MEDIUMCVSS 5.3v2.1v2.1.02023-06-16
CVE-2023-34165 [MEDIUM] CWE-862 CVE-2023-34165: Unauthorized access vulnerability in the Save for later feature provided by AI Touch.Successful expl
Unauthorized access vulnerability in the Save for later feature provided by AI Touch.Successful exploitation of this vulnerability may cause third-party apps to forge a URI for unauthorized access with zero permissions.
nvd
CVE-2026-41981P4MEDIUMCVSS 5.3v6.1.0v6.0.0+1 more2026-06-09
CVE-2026-41981 [MEDIUM] CWE-122 CVE-2026-41981: Out-of-bounds write vulnerability in the IPC module. Impact: Successful exploitation of this vulnera
Out-of-bounds write vulnerability in the IPC module. Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2022-48293P4MEDIUMCVSS 6.5v2.0v2.1.0+1 more2023-02-09
CVE-2022-48293 [MEDIUM] CWE-125 CVE-2022-48293: The Bluetooth module has an OOM vulnerability. Successful exploitation of this vulnerability may aff
The Bluetooth module has an OOM vulnerability. Successful exploitation of this vulnerability may affect data confidentiality.
nvd
CVE-2022-48292P4MEDIUMCVSS 6.5v2.0v2.1.0+1 more2023-02-09
CVE-2022-48292 [MEDIUM] CWE-125 CVE-2022-48292: The Bluetooth module has an out-of-memory (OOM) vulnerability. Successful exploitation of this vulne
The Bluetooth module has an out-of-memory (OOM) vulnerability. Successful exploitation of this vulnerability may affect data confidentiality.
nvd
CVE-2025-54648P4MEDIUMCVSS 6.5v5.1.02025-08-06
CVE-2025-54648 [MEDIUM] CWE-125 CVE-2025-54648: Out-of-bounds read vulnerability in the SSAP module of the NearLink protocol stack. Impact: Successf
Out-of-bounds read vulnerability in the SSAP module of the NearLink protocol stack.
Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2025-54647P4MEDIUMCVSS 6.5v5.1.02025-08-06
CVE-2025-54647 [MEDIUM] CWE-125 CVE-2025-54647: Out-of-bounds read vulnerability in the SSAP module of the NearLink protocol stack. Impact: Successf
Out-of-bounds read vulnerability in the SSAP module of the NearLink protocol stack.
Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2022-39006P4MEDIUMCVSS 5.9v2.0v2.12022-09-16
CVE-2022-39006 [MEDIUM] CWE-362 CVE-2022-39006: The MPTCP module has the race condition vulnerability. Successful exploitation of this vulnerability
The MPTCP module has the race condition vulnerability. Successful exploitation of this vulnerability may cause the device to restart.
nvd
CVE-2026-41968P4MEDIUMCVSS 5.9v6.1.0v6.0.0+1 more2026-05-15
CVE-2026-41968 [MEDIUM] CWE-840 CVE-2026-41968: Permission control vulnerability in the manufacturability design module. Impact: Successful exploita
Permission control vulnerability in the manufacturability design module. Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2026-41973P4MEDIUMCVSS 5.9v4.3.1v4.3.0+2 more2026-06-09
CVE-2026-41973 [MEDIUM] CWE-840 CVE-2026-41973: Permission control vulnerability in calls. Impact: Successful exploitation of this vulnerability may
Permission control vulnerability in calls. Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2026-41967P4MEDIUMCVSS 5.9v6.0.0v5.1.02026-05-15
CVE-2026-41967 [MEDIUM] CWE-840 CVE-2026-41967: Permission control vulnerability in the manufacturability design module. Impact: Successful exploita
Permission control vulnerability in the manufacturability design module. Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2026-41961P4MEDIUMCVSS 5.9v6.1.0v6.0.0+1 more2026-05-15
CVE-2026-41961 [MEDIUM] CWE-840 CVE-2026-41961: Permission control vulnerability in contacts. Impact: Successful exploitation of this vulnerability
Permission control vulnerability in contacts. Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2026-34855P4MEDIUMCVSS 5.7v4.0.0v4.2.0+4 more2026-04-13
CVE-2026-34855 [MEDIUM] CWE-20 CVE-2026-34855: Out-of-bounds write vulnerability in the kernel module. Impact: Successful exploitation of this vuln
Out-of-bounds write vulnerability in the kernel module.
Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.
nvd