CVE-2017-2707: Huawei Mate 9 Firmware

High severity, CVSS 7.1. EPSS: 0.3% chance of exploitation in the next 30 days.

Mate 9 smartphones with software MHA-AL00AC00B125 have a privilege escalation vulnerability in Push module. An attacker tricks a user to save a rich media into message on the smart phone, which could be exploited to cause the attacker to delete message or fake user to send message.

Affected products

  • Huawei Mate 9 Firmware: up to and including mha-al00ac00b125

Published 2017-11-22. Last modified 2026-06-17.