CVE-2017-2699: Huawei Honor 7 Firmware
High severity, CVSS 7.8. EPSS: 1% chance of exploitation in the next 30 days.
The Huawei Themes APP in versions earlier than PLK-UL00C17B385, versions earlier than CRR-L09C432B380, versions earlier than LYO-L21C577B128 has a privilege elevation vulnerability. An attacker could exploit this vulnerability to upload theme packs containing malicious files and trick users into installing the theme packets, resulting in the execution of arbitrary code.
Affected products
- Huawei Honor 7 Firmware: before plk-ul00c17b385 (fixed in plk-ul00c17b385)
- Huawei Lyo-l21 Firmware: before lyo-l21c577b128 (fixed in lyo-l21c577b128)
- Huawei Mate S Firmware: before crr-l09c432b380 (fixed in crr-l09c432b380)
Published 2017-11-22. Last modified 2026-06-17.