News

Vodafone finds Huawei vulnerabilities 'going back years'

Giulio Saggin
Giulio Saggin
Tuesday 28 November 2023

In a report to Bloomberg on April 30, Vodafone admits it "found vulnerabilities going back years with equipment supplied by Huawei for the carrier’s Italian business." They further admitted that "hidden backdoors in the software could have given Huawei unauthorized access to the carrier's fixed-line network in Italy, a system that provides internet service to millions of homes and businesses." The findings were set out in "briefing documents from 2009 and 2011" and Huawei responded that "it was made aware of historical vulnerabilities in 2011 and 2012 and they were addressed at the time." To make matters worse, the same (Huawei) security issues were also found in Germany, Spain, Portugal and the UK, where reports suggest they may be willing to let the company assist building its 5G network. Even before the report came to light, countries around the world were keeping Huawei at arms length. Australia, Japan and Taiwan are refusing to allow Huawei equipment on their 5G networks, while Canada and New Zealand are reviewing their association with the company. The US won't use Huawei, the world's second biggest selling smartphone brand, citing security reasons. Huawei have hit back: "Software vulnerabilities are an industry-wide challenge. Like every information and communications technology vendor, we have a well-established public notification and patching process, and when a vulnerability is identified, we work closely with our partners to take the appropriate corrective action ... There is absolutely no truth in the suggestion that Huawei conceals backdoors in its equipment." Even though Huawei have said the security flaws were addressed at the time, this years-old revelation won't do their reputation any good.

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2024 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203