CVE-2014-9135: Huawei p7-l10 Firmware

Medium severity, CVSS 4.3. EPSS: 0.8% chance of exploitation in the next 30 days.

The PackageInstaller module in Huawei P7-L10 smartphones before V100R001C00B136 allows remote attackers to spoof the origin website and bypass the website whitelist protection mechanism via a crafted package.

Affected products

  • Huawei p7-l10 Firmware: up to and including v100r001c00b135

Published 2014-12-19. Last modified 2026-06-17.