CVE-2017-2694: Huawei Vmall
Low severity, CVSS 3.3. EPSS: 0.5% chance of exploitation in the next 30 days.
The AlarmService component in HwVmall with software earlier than 1.5.2.0 versions has no control over calling permissions, allowing any third party to call. An attacker can construct a malicious application to call it. Consequently, alert music will be played suddenly, compromising user experience.
Affected products
- Huawei Vmall: before 1.5.2.0 (fixed in 1.5.2.0)
Published 2017-11-22. Last modified 2026-06-17.