CVE-2014-9135

Huawei P7-L10 Firmware < V100R001C00B136 - Website Whitelist Bypass via PackageInstaller Module

Title source: llm
STIX 2.1

Description

The PackageInstaller module in Huawei P7-L10 smartphones before V100R001C00B136 allows remote attackers to spoof the origin website and bypass the website whitelist protection mechanism via a crafted package.

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/99283

Scores

EPSS 0.0018
EPSS Percentile 39.8%

Details

CWE
CWE-264
Status published
Products (1)
huawei/p7-l10_firmware < v100r001c00b135
Published Dec 19, 2014
Tracked Since Feb 18, 2026