CVE-2017-17224: Huawei HG655M Firmware

High severity, CVSS 8.8. EPSS: 0.4% chance of exploitation in the next 30 days.

Some Huawei smart phones with versions earlier than Harry-AL00C 9.1.0.206(C00E205R3P1) have a null pointer dereference vulnerability. An attacker crafts specific packets and sends to the affected product to exploit this vulnerability. Successful exploitation may cause the affected phone abnormal.

Affected products

  • Huawei HG655M Firmware: before harry-al00c_9.1.0.206\(c00e205r3p1\) (fixed in harry-al00c_9.1.0.206\(c00e205r3p1\)); before v100r001c02b023 (fixed in v100r001c02b023)

Published 2019-11-12. Last modified 2026-06-17.