ZeroHour

CVE-2026-49310

Permission Control Flaw in Huawei Event Notification Module (CVE-2026-49310)

CVSS 3.1
8.6 high
EPSS
<1%p16
Published
()
Modified
AI analysis

CVE-2026-49310 is a permission control vulnerability (CWE-264) in the event notification module of an affected Huawei product, assigned by Huawei's PSIRT. According to the CVSS 3.1 vector, it is exploitable over the network without authentication, special privileges, or user interaction (AV:N/AC:L/PR:N/UI:N) and crosses a security scope boundary (S:C), with the vector rating the availability impact as high (A:H) while the vendor description notes the flaw may affect service confidentiality. An attacker who reaches the event notification module without proper access controls could impact the confidentiality and/or availability of the service, though the exact product, version ranges, and attack preconditions are not detailed in the available data. Any organization running the affected Huawei product should treat itself as potentially exposed until the product line and fixed versions are confirmed. As of now there is no known public proof-of-concept, no reported in-the-wild exploitation, and the CVE is not listed in CISA's Known Exploited Vulnerabilities catalog.

What to do: Monitor Huawei's PSIRT security advisories for the bulletin covering CVE-2026-49310 to identify the affected product, vulnerable version ranges, and fixed release, then apply the vendor patch as soon as it is published. In the interim, restrict unauthenticated network access to the affected product's event notification interfaces using ACLs or firewall rules, since the CVSS vector indicates network exploitability without privileges. Verify exposure by checking whether the event notification module of any Huawei deployment in your environment is reachable from untrusted networks.

Affected
Huawei
Estimated exposure
No basis for an estimate.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Permission control vulnerability in the event notification module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Weakness
CWE-264
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.