Vulnerabilities
Summary — last 7 days
New vulnerabilities2,856▼ 216 vs. last week
Critical / high1,332▼ 166 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)223▼ 98 vs. last week
8 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Modified | High (7.4) | 0.78% | — | Huawei Espace 7950 Firmware | 11/27/2018 | 6/17/2026 | There is a SRTP icon display vulnerability in Huawei eSpace product. An unauthenticated, remote attacker launches man-in-the-middle attack to intercept the packets in non-secure transmission mode. Successful exploitation may intercept and tamper with the call information, eventually cause sensitive information leak. | |
| Modified | Medium (5.9) | 0.78% | — | Huawei Espace 7950 Firmware | 11/27/2018 | 6/17/2026 | There is a short key vulnerability in Huawei eSpace product. An unauthenticated, remote attacker launches man-in-the-middle attack to intercept and decrypt the call information when the user enables SRTP to make a call. Successful exploitation may cause sensitive information leak. | |
| Modified | High (7.4) | 1.1% | — | Huawei Espace 7950 Firmware | 11/27/2018 | 6/17/2026 | There is an anonymous TLS cipher suites supported vulnerability in Huawei eSpace product. An unauthenticated, remote attacker launches man-in-the-middle attack to hijack the connection from a client when the user signs up to log in by TLS. Due to insufficient authentication, which may be exploited to intercept and… | |
| Modified | High (8.8) | 2.0% | — | Huawei Espace 7910 FirmwareHuawei Espace 7950 FirmwareHuawei Espace 8950 Firmware | 3/9/2018 | 6/17/2026 | Huawei eSpace 7910 V200R003C30; eSpace 7950 V200R003C30; eSpace 8950 V200R003C00; V200R003C30 have a directory traversal vulnerability. An authenticated, remote attacker can craft specific URL to the affected products. Due to insufficient verification of the URL, successful exploit will upload and download files and… | |
| Modified | High (8.8) | 1.2% | — | Huawei Espace 7950 FirmwareHuawei Espace 8950 Firmware | 3/9/2018 | 6/17/2026 | Import Language Package function in Huawei eSpace 7950 V200R003C30; eSpace 8950 V200R003C00; V200R003C30 has a remote code execution vulnerability. An authenticated, remote attacker can craft and send the packets to the affected products after Language Package is uploaded. Due to insufficient verification of the… | |
| Modified | High (8.8) | 1.2% | — | Huawei Espace 7950 FirmwareHuawei Espace 8950 Firmware | 3/9/2018 | 6/17/2026 | Import Signal Tone function in Huawei eSpace 7950 V200R003C30; eSpace 8950 V200R003C00; V200R003C30 has a remote code execution vulnerability. An authenticated, remote attacker can craft and send the packets to the affected products after the Signal Tone is uploaded. Due to insufficient verification of the packets,… | |
| Modified | High (8.8) | 1.2% | — | Huawei Dp300 FirmwareHuawei Te60 FirmwareHuawei Tp3106 FirmwareHuawei Viewpoint 9030 Firmware+4 | 11/22/2017 | 6/17/2026 | DP300 V500R002C00,TE60 with software V100R001C01, V100R001C10, V100R003C00, V500R002C00 and V600R006C00,TP3106 with software V100R001C06 and V100R002C00,ViewPoint 9030 with software V100R011C02, V100R011C03,eCNS210_TD with software V100R004C10,eSpace 7950 with software V200R003C00 and V200R003C30,eSpace IAD with… | |
| Modified | High (7.5) | 1.0% | — | Huawei Espace 7950Huawei Espace 7910 | 1/11/2016 | 6/17/2026 | Huawei eSpace 7910 and 7950 IP phones with software before V200R002C00SPC800 allow remote attackers with established sessions to cause a denial of service (device restart) via unspecified packets. |