ALE-L02C635B140 and earlier versions,ALE-L02C636B140 and earlier versions,ALE-L21C10B150 and earlier versions,ALE-L21C185B200 and earlier versions,ALE-L21C432B214 and earlier versions,ALE-L21C464B150 and earlier versions,ALE-L21C636B200 and earlier versions,ALE-L23C605B190 and earlier versions,ALE-TL00C01B250 and earlier versions,ALE-UL00C00B250 and earlier versions,MT7-L09C605B325 and earlier versions,MT7-L09C900B339 and earlier versions,MT7-TL10C900B339 and earlier versions,CRR-CL00C92B172 and earlier versions,CRR-L09C432B180 and earlier versions,CRR-TL00C01B172 and earlier versions,CRR-UL00C00B172 and earlier versions,CRR-UL20C432B171 and earlier versions,GRA-CL00C92B230 and earlier versions,GRA-L09C432B222 and earlier versions,GRA-TL00C01B230SP01 and earlier versions,GRA-UL00C00B230 and earlier versions,GRA-UL00C10B201 and earlier versions,GRA-UL00C432B220 and earlier versions,H60-L04C10B523 and earlier versions,H60-L04C185B523 and earlier versions,H60-L04C636B527 and earlier versions,H60-L04C900B530 and earlier versions,PLK-AL10C00B220 and earlier versions,PLK-AL10C92B220 and earlier versions,PLK-CL00C92B220 and earlier versions,PLK-L01C10B140 and earlier versions,PLK-L01C185B130 and earlier versions,PLK-L01C432B187 and earlier versions,PLK-L01C432B190 and earlier versions,PLK-L01C432B190 and earlier versions,PLK-L01C636B130 and earlier versions,PLK-TL00C01B220 and earlier versions,PLK-TL01HC01B220 and earlier versions,PLK-UL00C17B220 and earlier versions,ATH-AL00C00B210 and earlier versions,ATH-AL00C92B200 and earlier versions,ATH-CL00C92B210 and earlier versions,ATH-TL00C01B210 and earlier versions,ATH-TL00HC01B210 and earlier versions,ATH-UL00C00B210 and earlier versions,RIO-AL00C00B220 and earlier versions,RIO-CL00C92B220 and earlier versions,RIO-TL00C01B220 and earlier versions,RIO-UL00C00B220 and earlier versions have a path traversal vulnerability
Published Nov 22, 2017
7.8
HIGHCVSS 3.0
EPSS 1.05%
Description
ALE-L02C635B140 and earlier versions,ALE-L02C636B140 and earlier versions,ALE-L21C10B150 and earlier versions,ALE-L21C185B200 and earlier versions,ALE-L21C432B214 and earlier versions,ALE-L21C464B150 and earlier versions,ALE-L21C636B200 and earlier versions,ALE-L23C605B190 and earlier versions,ALE-TL00C01B250 and earlier versions,ALE-UL00C00B250 and earlier versions,MT7-L09C605B325 and earlier versions,MT7-L09C900B339 and earlier versions,MT7-TL10C900B339 and earlier versions,CRR-CL00C92B172 and earlier versions,CRR-L09C432B180 and earlier versions,CRR-TL00C01B172 and earlier versions,CRR-UL00C00B172 and earlier versions,CRR-UL20C432B171 and earlier versions,GRA-CL00C92B230 and earlier versions,GRA-L09C432B222 and earlier versions,GRA-TL00C01B230SP01 and earlier versions,GRA-UL00C00B230 and earlier versions,GRA-UL00C10B201 and earlier versions,GRA-UL00C432B220 and earlier versions,H60-L04C10B523 and earlier versions,H60-L04C185B523 and earlier versions,H60-L04C636B527 and earlier versions,H60-L04C900B530 and earlier versions,PLK-AL10C00B220 and earlier versions,PLK-AL10C92B220 and earlier versions,PLK-CL00C92B220 and earlier versions,PLK-L01C10B140 and earlier versions,PLK-L01C185B130 and earlier versions,PLK-L01C432B187 and earlier versions,PLK-L01C432B190 and earlier versions,PLK-L01C432B190 and earlier versions,PLK-L01C636B130 and earlier versions,PLK-TL00C01B220 and earlier versions,PLK-TL01HC01B220 and earlier versions,PLK-UL00C17B220 and earlier versions,ATH-AL00C00B210 and earlier versions,ATH-AL00C92B200 and earlier versions,ATH-CL00C92B210 and earlier versions,ATH-TL00C01B210 and earlier versions,ATH-TL00HC01B210 and earlier versions,ATH-UL00C00B210 and earlier versions,RIO-AL00C00B220 and earlier versions,RIO-CL00C92B220 and earlier versions,RIO-TL00C01B220 and earlier versions,RIO-UL00C00B220 and earlier versions have a path traversal vulnerability. An attacker may exploit it to decompress malicious files into a target path.
Affected products
- Vendor Huawei Technologies Co., Ltd. Product P8 Lite,Mate 7,Mate S,P8,honor 6,honor 7,SHOTX,G8, Defaultn/a
- Version ALE-L02C635B140 and earlier versions,ALE-L02C636B140 and earlier versions,ALE-L21C10B150 and earlier versions,ALE-L21C185B200 and earlier versions,ALE-L21C432B214 and earlier versions,ALE-L21C464B150 and earlier versions,ALE-L21C636B200 and earlier versions,ALE-L23C605B190 and earlier versions,ALE-TL00C01B250 and earlier versions,ALE-UL00C00B250 and earlier versions,MT7-L09C605B325 and earlier versions,MT7-L09C900B339 and earlier versions,MT7-TL10C900B339 and earlier versions,CRR-CL00C92B172 and earlier versions,CRR-L09C432B180 and earlier versions,CRR-TL00C01B172 and earlier versions,CRR-UL00C00B172 and earlier versions,CRR-UL20C432B171 and earlier versions,GRA-CL00C92B230 and earlier versions,GRA-L09C432B222 and earlier versions,GRA-TL00C01B230SP01 and earlier versions,GRA-UL00C00B230 and earlier versions,GRA-UL00C10B201 and earlier versions,GRA-UL00C432B220 and earlier versions,H60-L04C10B523 and earlier versions,H60-L04C185B523 and earlier versions,H60-L04C636B527 and earlier versions,H60- ...[truncated*]StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Huawei Technologies Co., Ltd. | P8 Lite,Mate 7,Mate S,P8,honor 6,honor 7,SHOTX,G8, | n/a |
|
Configuration 1
- ≤ ale-l02c635b140
Configuration 2
- ≤ ale-l02c636b140
Configuration 3
- ≤ ale-l21c10b150
Configuration 4
- ≤ ale-l21c185b200
Configuration 5
- ≤ ale-l21c432b214
Configuration 6
- ≤ ale-l21c464b150
Configuration 7
- ≤ ale-l21c636b200
Configuration 8
- ≤ ale-l23c605b190
Configuration 9
- ≤ ale-tl00c01b250
Configuration 10
- ≤ ale-ul00c00b250.
Configuration 11
- ≤ mt7-l09c605b325
Configuration 12
- ≤ mt7-l09c900b339
Configuration 13
- ≤ mt7-tl10c900b339
Configuration 14
- ≤ crr-cl00c92b172
Configuration 15
- ≤ crr-l09c432b180
Configuration 16
- ≤ crr-tl00c01b172
Configuration 17
- ≤ crr-ul00c00b172
Configuration 18
- ≤ crr-ul20c432b171
Configuration 19
- ≤ gra-cl00c92b230
Configuration 20
- ≤ gra-l09c432b222
Configuration 21
- ≤ gra-tl00c01b230sp01
Configuration 22
- ≤ gra-ul00c00b230
Configuration 23
- ≤ gra-ul00c10b201
Configuration 24
- ≤ gra-ul00c432b220
Configuration 25
- ≤ h60-l04c10b523
Configuration 26
- ≤ h60-l04c185b523
Configuration 27
- ≤ h60-l04c636b527
Configuration 28
- ≤ h60-l04c900b530
Configuration 29
- ≤ plk-al10c00b220
Configuration 30
- ≤ plk-al10c92b220
Configuration 31
- ≤ plk-cl00c92b220
Configuration 32
- ≤ plk-l01c10b140
Configuration 33
- ≤ plk-l01c10b140
Configuration 34
- ≤ plk-l01c432b187
Configuration 35
- ≤ plk-l01c432b190
Configuration 36
- ≤ plk-l01c636b130
Configuration 37
- ≤ plk-tl00c01b220
Configuration 38
- ≤ plk-tl01hc01b220
Configuration 39
- ≤ plk-ul00c17b220
Configuration 40
- ≤ ath-al00c92b200
Configuration 41
- ≤ ath-cl00c92b210
Configuration 42
- ≤ ath-tl00c01b210
Configuration 43
- ≤ ath-tl00hc01b210
Configuration 44
- ≤ ath-ul00c00b210
Configuration 45
- ≤ rio-al00c00b220
Configuration 46
- ≤ ath-al00c00b210
Configuration 47
- ≤ rio-al00c00b220
Configuration 48
- ≤ rio-cl00c92b220
Configuration 49
- ≤ rio-tl00c01b220
Configuration 50
- ≤ rio-ul00c00b220
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
AV:N/AC:M/Au:N/C:P/I:P/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
Percentile over time
- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
Table of values (10 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 1.05% (0.01052) | 63.05th | v5 (v2026.06.15) |
| Sep 20, 2026 | 1.05% (0.01052) | 62.82th | v5 (v2026.06.15) |
| Jul 20, 2024 | 0.06% (0.00062) | 27.19th | v3 (v2023.03.01) |
| Jun 14, 2024 | 0.06% (0.00062) | 26.68th | v3 (v2023.03.01) |
| Sep 3, 2023 | 0.06% (0.00062) | 24.68th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.05% (0.00054) | 19.63th | v3 (v2023.03.01) |
| Mar 6, 2023 | 0.89% (0.00885) | 27.89th | v2 (v2022.01.01) |
| Feb 4, 2022 | 0.89% (0.00885) | 10.50th | v2 (v2022.01.01) |
| Feb 3, 2022 | 0.62% (0.00624) | 17.80th | v5 (v2026.06.15) |
| Apr 14, 2021 | 0.62% (0.00624) | 0.00th | v1 |
References (2)
- http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20170125-01-emui-en x_refsource_CONFIRMIssue TrackingVendor Advisory
- http://www.securityfocus.com/bid/95919 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
| Link | Providers | Tags |
|---|---|---|
| http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20170125-01-emui-en | x_refsource_CONFIRMIssue TrackingVendor Advisory | |
| http://www.securityfocus.com/bid/95919 | vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry |
Change history (0)
No recorded changes yet.