CVE-2017-8175: Huawei Vicky-AL00A

Medium severity, CVSS 5.5. EPSS: 0.6% chance of exploitation in the next 30 days.

The Bastet of some Huawei mobile phones with software earlier than Vicky-AL00AC00B167 versions, earlier than Victoria-AL00AC00B167 versions, earlier than Warsaw-AL00C00B191 versions has an insufficient input validation vulnerability due to the lack of parameter validation. An attacker may trick a user into installing a malicious APP. The APP can modify specific parameter to cause system reboot.

Affected products

  • Huawei Vicky-AL00A: before vicky-al00ac00b167 (fixed in vicky-al00ac00b167)
  • Huawei Victoria-AL00A: before victoria-al00ac00b167 (fixed in victoria-al00ac00b167)
  • Huawei Warsaw-AL00: before warsaw-al00c00b191 (fixed in warsaw-al00c00b191)

Published 2017-11-22. Last modified 2026-06-17.