Huawei HarmonyOS Path Traversal Vulnerability in Virtualization File Module

Vulnerability

A path traversal vulnerability has been identified in the virtualization file module of Huawei HarmonyOS versions 5.0.1 and 5.0.2. This vulnerability could be exploited to manipulate file paths, potentially leading to unauthorized access to files outside of the intended directory. Successful exploitation may compromise the confidentiality of the virtualization file module.

Impact

Exploitation of this vulnerability could lead to unauthorized access to sensitive files, thereby affecting the confidentiality of information within the virtualization file module.

Remediation

Users can refer to the Huawei August 2025 Security Update for instructions on applying the necessary patches.

Added: Aug 6, 2025, 1:17 AM
Updated: Aug 6, 2025, 1:17 AM

Vulnerability Rating

Custom Algorithm
spread
7.8
impact
0.6
exploitability
3.3
remediation
0.0
relevance
0.3
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.