CVE-2021-37104

HIGH

HUAWEI P40 Firmware 10.1.0.118(C00E116R3P3) - Server-Side Request Forgery

Title source: llm
STIX 2.1

Description

There is a server-side request forgery vulnerability in HUAWEI P40 versions 10.1.0.118(C00E116R3P3). This vulnerability is due to insufficient validation of parameters while dealing with some messages. A successful exploit could allow the attacker to gain access to certain resource which the attacker are supposed not to do.

References (1)

Core 1

Scores

CVSS v3 7.5
EPSS 0.0013
EPSS Percentile 31.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-918
Status published
Products (1)
huawei/p40_firmware 10.1.0.118\(c00e116r3p3\)
Published Sep 28, 2021
Tracked Since Feb 18, 2026