CVE-2018-7988: Huawei Mate 9 Pro Firmware

Medium severity, CVSS 4.6. EPSS: 0.2% chance of exploitation in the next 30 days.

There is a Factory Reset Protection (FRP) bypass vulnerability on several smartphones. The system does not sufficiently verify the permission, an attacker uses a data cable to connect the smartphone to another smartphone and then perform a series of specific operations. Successful exploit could allow the attacker bypass the FRP protection.

Affected products

  • Huawei Mate 9 Pro Firmware: before 8.0.0.363\(c00\) (fixed in 8.0.0.363\(c00\))
  • Huawei Nova 2 Plus Firmware: before 8.0.0.350\(c00\) (fixed in 8.0.0.350\(c00\))

Published 2018-11-27. Last modified 2026-06-17.