CVE-2025-54611

CVE Details

Basic Information

Title CVE-2025-54611
Type cve
Published 2025-08-06T01:18:18.740Z
Modified 2025-08-06T01:18:18.740Z

Product Information

Vendor Huawei
Product HarmonyOS
Version 4.3.1

CVSS Information

Base Score 7.3 (HIGH)
Attack Vector CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L

AI Analysis

AI Description A vulnerability in the Gallery module of Huawei HarmonyOS could allow unauthorized access to sensitive information, potentially compromising service confidentiality.
AI Severity High
AI Vendor Huawei
AI Product HarmonyOS
AI Version 2.0.0, 2.1.0, 3.0.0, 3.1.0, 4.0.0, 4.2.0, 4.3.0, 4.3.1

Affected Products

  • Huawei HarmonyOS 4.3.1
  • Huawei HarmonyOS 4.3.0
  • Huawei HarmonyOS 4.2.0
  • Huawei HarmonyOS 4.0.0
  • Huawei HarmonyOS 3.1.0
  • Huawei HarmonyOS 3.0.0
  • Huawei HarmonyOS 2.1.0
  • Huawei HarmonyOS 2.0.0
  • Huawei EMUI 15.0.0
  • Huawei EMUI 14.0.0
  • Huawei EMUI 13.0.0
  • Huawei EMUI 12.0.0

Additional Information

CWE List CWE-840
Source huawei

Description

EXTRA_REFERRER resource read vulnerability in the Gallery module.
Impact: Successful exploitation of this vulnerability may affect service confidentiality.

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.