First published: Wed Apr 28 2021(Updated: )
There is a JavaScript injection vulnerability in certain Huawei smartphones. A module does not verify some inputs sufficiently. Attackers can exploit this vulnerability by sending a malicious application request to launch JavaScript injection. This may compromise normal service. Affected product versions include HUAWEI P30 versions earlier than 10.1.0.165(C01E165R2P11), 11.0.0.118(C635E2R1P3), 11.0.0.120(C00E120R2P5), 11.0.0.138(C10E4R5P3), 11.0.0.138(C185E4R7P3), 11.0.0.138(C432E8R2P3), 11.0.0.138(C461E4R3P3), 11.0.0.138(C605E4R1P3), and 11.0.0.138(C636E4R3P3).
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei P30 Firmware | <10.1.0.165\(c01e165r2p11\) | |
HUAWEI P30 | ||
Huawei P30 Firmware | <11.0.0.118\(c635e2r1p3\) | |
Huawei P30 Firmware | <11.0.0.120\(c00e120r2p5\) | |
Huawei P30 Firmware | <11.0.0.138\(c10e4r5p3\) | |
Huawei P30 Firmware | <11.0.0.138\(c185e4r7p3\) | |
Huawei P30 Firmware | <11.0.0.138\(c432e8r2p3\) | |
Huawei P30 Firmware | <11.0.0.138\(c461e4r3p3\) | |
Huawei P30 Firmware | <11.0.0.138\(c605e4r1p3\) | |
Huawei P30 Firmware | <11.0.0.138\(c636e4r3p3\) |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-22331 is a JavaScript injection vulnerability in certain Huawei smartphones.
Attackers can exploit CVE-2021-22331 by sending a malicious application request to launch JavaScript injection.
CVE-2021-22331 can compromise normal service on the affected Huawei smartphones.
The Huawei P30 Firmware versions up to 10.1.0.165(c01e165r2p11) and versions 11.0.0.118(c635e2r1p3), 11.0.0.120(c00e120r2p5), 11.0.0.138(c10e4r5p3), 11.0.0.138(c185e4r7p3), 11.0.0.138(c432e8r2p3), 11.0.0.138(c461e4r3p3), 11.0.0.138(c605e4r1p3), 11.0.0.138(c636e4r3p3) are affected.
It is recommended to update the firmware of the affected Huawei smartphones to the latest version available.