Skip to main content
DashboardThreatsMapFeedsAPI
reconnecting
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

CVE-2025-54654: CWE-264 Permissions, Privileges, and Access Controls in Huawei HarmonyOS

0
Medium
VulnerabilityCVE-2025-54654cvecve-2025-54654cwe-264
Published: Sat Oct 11 2025 (10/11/2025, 01:50:10 UTC)
Source: CVE Database V5
Vendor/Project: Huawei
Product: HarmonyOS

Description

Permission control vulnerability in the Gallery module. Successful exploitation of this vulnerability may affect service confidentiality

AI-Powered Analysis

AILast updated: 10/11/2025, 02:33:27 UTC

Technical Analysis

CVE-2025-54654 is a permission control vulnerability classified under CWE-264 affecting the Gallery module of Huawei's HarmonyOS versions 5.0.1 and 5.1.0. The vulnerability arises from improper enforcement of permissions within the Gallery application, which could allow an unauthorized local attacker to cause a denial of service (DoS) condition. According to the CVSS 3.1 vector (AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H), the attack requires local access but no privileges or user interaction, indicating that any local user or process could exploit this flaw with low complexity. The vulnerability does not compromise confidentiality or integrity but impacts availability by potentially disrupting the Gallery service or related system components. No known exploits have been reported in the wild, and Huawei has not yet released patches. The vulnerability was reserved in July 2025 and published in October 2025. The lack of patches and the medium severity score suggest that while the risk is not critical, it could still disrupt device functionality, especially in environments where HarmonyOS devices are used extensively. The Gallery module is a core user-facing application, so disruption could affect user experience and operational continuity.

Potential Impact

For European organizations, the primary impact of CVE-2025-54654 is the potential for denial of service on devices running affected HarmonyOS versions. This could disrupt workflows relying on Huawei devices, particularly those using the Gallery app for media management or other integrated services. While confidentiality and integrity are not directly impacted, availability issues could lead to operational delays or loss of productivity. In sectors where device availability is critical, such as telecommunications, public services, or enterprises with Huawei device deployments, this vulnerability could pose a moderate operational risk. Additionally, the requirement for local access limits remote exploitation, but insider threats or compromised local environments could leverage this vulnerability. The absence of patches means organizations must rely on compensating controls until updates are available. Given Huawei's market presence in Europe, especially in countries with significant Huawei device usage, the impact could be more pronounced in those regions.

Mitigation Recommendations

1. Restrict physical and local access to devices running HarmonyOS to trusted personnel only, minimizing the risk of local exploitation. 2. Implement strict device usage policies and monitor for unusual activity on Huawei devices, particularly focusing on the Gallery app and related processes. 3. Employ endpoint detection and response (EDR) solutions capable of identifying anomalous behavior indicative of exploitation attempts. 4. Regularly audit device configurations and permissions to ensure no unauthorized privilege escalations or access exist. 5. Coordinate with Huawei for timely updates and patches; prioritize patch deployment once available. 6. Consider temporary disabling or limiting use of the Gallery module in sensitive environments if feasible until a patch is released. 7. Educate users about the risks of local device access and enforce strong physical security controls. 8. Maintain up-to-date backups of critical data to mitigate potential service disruptions.

Need more detailed analysis?Get Pro

Technical Details

Data Version
5.1
Assigner Short Name
huawei
Date Reserved
2025-07-28T03:55:34.533Z
Cvss Version
3.1
State
PUBLISHED

Threat ID: 68e9be7854cfe91d8fec883f

Added to database: 10/11/2025, 2:18:32 AM

Last enriched: 10/11/2025, 2:33:27 AM

Last updated: 10/11/2025, 12:52:28 PM

Views: 5

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis are available only with a Pro account. Contact root@offseq.com for access.

Please log in to the Console to use AI analysis features.

Need enhanced features?

Contact root@offseq.com for Pro access with improved analysis and higher rate limits.

Latest Threats