Some Huawei smartphones with software AGS-L09C233B019,AGS-W09C233B019,KOB-L09C233B017,KOB-W09C233B012 have a type confusion vulnerability. The program initializes a variable using one type, but it later accesses that variable using a type that is different with the original type when do certain register operation. Successful exploit could result in buffer overflow then may cause malicious code execution.
2017-11-22T19:29:03.677
2025-04-20T01:37:25.860
Deferred
CVSSv3.0: 7.8 (HIGH)
AV:N/AC:M/Au:N/C:C/I:C/A:C
8.6
10.0
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Operating System | huawei | agassi-l09hn_firmware | ags-l09c233b019 | Yes |
| Hardware | huawei | agassi-l09hn | - | No |
| Operating System | huawei | agassi-w09hn_firmware | ags-w09c233b019 | Yes |
| Hardware | huawei | agassi-w09hn | - | No |
| Operating System | huawei | kobe-l09ahn_firmware | kob-l09c233b017 | Yes |
| Hardware | huawei | kobe-l09ahn | - | No |
| Operating System | huawei | kobe-w09chn_firmware | kob-w09c233b012 | Yes |
| Hardware | huawei | kobe-w09chn | - | No |