Authentication bypass vulnerability in the device authentication module. Impact: Successful exploitation of this vulnerability will affect integrity and confidentiality.
The vulnerability classified as CWE-305 (Authentication Bypass by Primary Weakness) results from a faulty implementation of the device authentication module in the HarmonyOS system. An attacker located on the same local network (vector AV:A) can bypass authentication mechanisms without possessing any privileges and without requiring user interaction. The attack scope extends beyond the targeted component (S:C), indicating the possibility of affecting other system resources.
Successful exploitation of the vulnerability leads to violations of data integrity and confidentiality in the system. An attacker can gain unauthorized access to protected resources and device functions by bypassing access control mechanisms.
Apply patches available from the manufacturer according to the references — Huawei security bulletins from March 2026 available at: https://consumer.huawei.com/en/support/bulletin/2026/3/, https://consumer.huawei.com/en/support/bulletinlaptops/2026/3/, https://consumer.huawei.com/en/support/bulletinvision/2026/3/
Devices running Huawei HarmonyOS — specific versions indicated in the manufacturer's references (Huawei security bulletins from March 2026, covering consumer devices, laptops, and Vision series devices).
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HHuawei Harmonyos
OSHuawei5.1.06.0.0
Related vulnerabilities
HarmonyOS: przepełnienie bufora sterty (heap buffer overflow) w module WEB
Błąd kontroli uprawnień w module zarządzania pamięcią Huawei HarmonyOS
Nieobsłużony wyjątek w module Graphics systemów Huawei EMUI/HarmonyOS
Podatność kontroli dostępu w module weryfikacji bezpieczeństwa Huawei
Ominięcie weryfikacji nazwy pakietu w module HwIms (Huawei EMUI/HarmonyOS)