Huawei HarmonyOS Medialibrary Module Path Traversal Vulnerability

Vulnerability

A path traversal vulnerability has been identified in the Medialibrary module of Huawei's HarmonyOS. This vulnerability affects several versions, including HarmonyOS 3.0.0, 2.0.0, 2.1.0, EMUI 13.0.0, and EMUI 12.0.0. Successful exploitation of this vulnerability could lead to unauthorized access to files, allowing attackers to read or modify data outside of the intended directory structure, thereby impacting the integrity and confidentiality of the system.

Impact

Exploitation of this vulnerability could result in unauthorized file access, allowing for potential data manipulation or disclosure.

Remediation

Users can refer to the January 2025 Huawei Security Bulletin for guidance on applying the available patch.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
7.8
impact
5.0
exploitability
4.7
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.