CVE-2017-17140: Huawei Enjoy 5s Firmware

Medium severity, CVSS 5.5. EPSS: 0.6% chance of exploitation in the next 30 days.

Huawei Enjoy 5s and Y6 Pro smartphones with software the versions before TAG-AL00C92B170; the versions before TIT-L01C576B121 have an information leak vulnerability due to the lack of parameter validation. An attacker tricks a user into installing a malicious application on the smart phone and the application can read some sensitive information in kernel memory which may cause sensitive information leak.

Affected products

  • Huawei Enjoy 5s Firmware: before tag-al00c92b170 (fixed in tag-al00c92b170)
  • Huawei y6 Pro Firmware: before tit-l01c576b121 (fixed in tit-l01c576b121)

Published 2018-03-05. Last modified 2026-06-17.