CVE-2017-15309: Huawei Ireader

High severity, CVSS 7.1. EPSS: 1% chance of exploitation in the next 30 days.

Huawei iReader app before 8.0.2.301 has a path traversal vulnerability due to insufficient validation on file storage paths. An attacker can exploit this vulnerability to store downloaded malicious files in an arbitrary directory.

Affected products

  • Huawei Ireader: before 8.0.2.301 (fixed in 8.0.2.301)

Published 2017-12-22. Last modified 2026-06-17.