CVE-2017-17140: Huawei Enjoy 5s Firmware
Medium severity, CVSS 5.5. EPSS: 0.6% chance of exploitation in the next 30 days.
Huawei Enjoy 5s and Y6 Pro smartphones with software the versions before TAG-AL00C92B170; the versions before TIT-L01C576B121 have an information leak vulnerability due to the lack of parameter validation. An attacker tricks a user into installing a malicious application on the smart phone and the application can read some sensitive information in kernel memory which may cause sensitive information leak.
Affected products
- Huawei Enjoy 5s Firmware: before tag-al00c92b170 (fixed in tag-al00c92b170)
- Huawei y6 Pro Firmware: before tit-l01c576b121 (fixed in tit-l01c576b121)
Published 2018-03-05. Last modified 2026-06-17.