CVE-2017-15309: Huawei Ireader
High severity, CVSS 7.1. EPSS: 1% chance of exploitation in the next 30 days.
Huawei iReader app before 8.0.2.301 has a path traversal vulnerability due to insufficient validation on file storage paths. An attacker can exploit this vulnerability to store downloaded malicious files in an arbitrary directory.
Affected products
- Huawei Ireader: before 8.0.2.301 (fixed in 8.0.2.301)
Published 2017-12-22. Last modified 2026-06-17.