CVE-2017-17159: Huawei MT8-EMUI4.1 Firmware

Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.

Some Huawei smart phones with software of NXT-AL10C00B386, NXT-CL00C92B386, NXT-DL00C17B386, NXT-TL00C01B386SP01, NTS-AL00C00B535 have a DoS vulnerability due to insufficient input validation. An unauthenticated attacker could send malformed System Information(SI) messages to the smart phone within radio range by special wireless device. Successful exploit could make the smart phone restart.

Affected products

  • Huawei MT8-EMUI4.1 Firmware: version nxt-al10c00b386 only; version nxt-cl00c92b386 only; version nxt-dl00c17b386 only; version nxt-tl00c01b386sp01 only
  • Huawei Nts-AL00 Firmware: version nts-al00c00b535 only

Published 2018-02-15. Last modified 2026-06-17.