Back to Database
Status published
Medium
CVE-2014-9135
The PackageInstaller module in Huawei P7-L10 smartphones before V100R001C00B136 allows...
Vulnerability Description
The PackageInstaller module in Huawei P7-L10 smartphones before V100R001C00B136 allows remote attackers to spoof the origin website and bypass the website whitelist protection mechanism via a crafted package.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2014-9135
Credits & Attribution
No credits recorded in the NVD database.
References
More from huawei
View All →CVE-2024-45441
Input verification vulnerability in the system service module
Impact: Successful exploitation...
Medium
6.2
CVE-2021-40042
There is a release of invalid pointer vulnerability in some...
Medium
6.5
CVE-2021-40033
There is an information exposure vulnerability on several Huawei Products....
Medium
5.5
CVE-2018-7932
Huawei AppGallery versions before 8.0.4.301 has an arbitrary Javascript running...
High
8.8
CVE-2017-2697
The goldeneye driver in NMO-L31C432B120 and earlier versions,NEM-L21C432B100 and earlier...
High
7.8
Affected Vendor
huawei
View all reports →Affected Software
p7-l10 firmware
Vulnerable Versions:
0
Timeline
Official Publish:
December 19th, 2014
Last Modified:
August 6th, 2024
Added to House:
July 19th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.