SecLens 情报中心

网安资讯,一网打尽。汇集权威漏洞通告与行业要闻,结合分组浏览、智能过滤、RSS订阅 和 Webhook 推送,多通道拓展您的安全情报视野。

厂商发布

厂商对产品安全、配置或策略的更新说明。

  • Fastjson RCE Vulnerability in Some Huawei Products

    发布时间 2026-07-24 08:00 (UTC+08:00) 抓取时间 2026-07-24 15:40 (UTC+08:00)

    The open-source software Fastjson used by some Huawei products has a Remote Code Execution (RCE) vulnerability. A remote attacker can exploit this vulnerability by sending crafted JSON data. Successful exploitation of this vulnerability may lead to remote code execution. (Vulnerability ID:HWPSIRT-2026-17473) This vulnerability has been assigned a Common Vuln

    扩展字段
    {
      "hw_psirt_ids": [
        "HWPSIRT-2026-17473"
      ],
      "language": "en",
      "sasn_no": "huawei-sa-FRViSHP-03027879",
      "sasn_version": "1.0",
      "severity": "Critical",
      "vulnerabilities": [
        {
          "cveId": "CVE-2026-16723",
          "hwPsirtId": "HWPSIRT-2026-17473"
        }
      ]
    }
    华为安全公告 Critical cve official_bulletin
  • Apache Tomcat Improper Input Validation Vulnerability in Some Huawei Products

    发布时间 2026-07-22 08:00 (UTC+08:00) 抓取时间 2026-07-22 21:42 (UTC+08:00)

    The open-source software Apache Tomcat used by some Huawei products has an improper input validation vulnerability. Successful exploitation could lead to unexpected application behavior. (Vulnerability ID:HWPSIRT-2026-43815) This vulnerability has been assigned a Common Vulnerabilities and Exposures (CVE) ID:CVE-2026-41293

    扩展字段
    {
      "hw_psirt_ids": [
        "HWPSIRT-2026-43815"
      ],
      "language": "en",
      "sasn_no": "huawei-sa-ATIIVViSHP-01234759",
      "sasn_version": "1.2",
      "severity": "Critical",
      "vulnerabilities": [
        {
          "cveId": "CVE-2026-41293",
          "hwPsirtId": "HWPSIRT-2026-43815"
        }
      ]
    }
    华为安全公告 Critical cve official_bulletin
  • Google Go Memory Corruption Vulnerability in Some Huawei Products

    发布时间 2026-07-22 08:00 (UTC+08:00) 抓取时间 2026-07-22 21:42 (UTC+08:00)

    The open-source software Google Go used by some Huawei products has a security vulnerability when slices and arrays are accessed by inductive variables. Attackers may exploit this vulnerability to cause memory corruption. (Vulnerability ID:HWPSIRT-2026-55220) This vulnerability has been assigned a Common Vulnerabilities and Exposures (CVE) ID:CVE-2026-27143

    扩展字段
    {
      "hw_psirt_ids": [
        "HWPSIRT-2026-55220"
      ],
      "language": "en",
      "sasn_no": "huawei-sa-GGMCViSHP-42231635",
      "sasn_version": "1.0",
      "severity": "Critical",
      "vulnerabilities": [
        {
          "cveId": "CVE-2026-27143",
          "hwPsirtId": "HWPSIRT-2026-55220"
        }
      ]
    }
    华为安全公告 Critical cve official_bulletin
  • Apache CXF LDAP Injection Vulnerability in Some Huawei Products

    发布时间 2026-07-22 08:00 (UTC+08:00) 抓取时间 2026-07-22 21:42 (UTC+08:00)

    The open-source software Apache CXF used by some Huawei products has an LDAP Injection vulnerability in the LDAP Certificate repository of the XKMS server. Successful exploitation of this vulnerability may allow attackers to retrieve arbitrary certificates from the repository. (Vulnerability ID:HWPSIRT-2026-42762) This vulnerability has been assigned a Commo

    扩展字段
    {
      "hw_psirt_ids": [
        "HWPSIRT-2026-42762"
      ],
      "language": "en",
      "sasn_no": "huawei-sa-ACLIViSHP-33812386",
      "sasn_version": "1.2",
      "severity": "Critical",
      "vulnerabilities": [
        {
          "cveId": "CVE-2026-44930",
          "hwPsirtId": "HWPSIRT-2026-42762"
        }
      ]
    }
    华为安全公告 Critical cve official_bulletin
  • Linux kernel Race Condition Vulnerability in Some Huawei Products

    发布时间 2026-07-22 08:00 (UTC+08:00) 抓取时间 2026-07-22 21:42 (UTC+08:00)

    The open-source operating system core Linux kernel used by some Huawei products has a race condition vulnerability. Successful exploitation of this vulnerability may lead to denial of service (DoS). (Vulnerability ID:HWPSIRT-2026-07909) This vulnerability has been assigned a Common Vulnerabilities and Exposures (CVE) ID:CVE-2026-23240

    扩展字段
    {
      "hw_psirt_ids": [
        "HWPSIRT-2026-07909"
      ],
      "language": "en",
      "sasn_no": "huawei-sa-LkRCViSHP-99516848",
      "sasn_version": "1.3",
      "severity": "Critical",
      "vulnerabilities": [
        {
          "cveId": "CVE-2026-23240",
          "hwPsirtId": "HWPSIRT-2026-07909"
        }
      ]
    }
    华为安全公告 Critical cve official_bulletin
  • Spring Boot Improper Certificate Validation Vulnerability in Some Huawei Products

    发布时间 2026-07-22 08:00 (UTC+08:00) 抓取时间 2026-07-22 21:42 (UTC+08:00)

    The open-source software Spring Boot used by some Huawei products has an improper certificate validation vulnerability. Successful exploitation of this vulnerability may enable a man-in-the-middle attack, potentially leading to information disclosure, data tampering, or denial of service (DoS). (Vulnerability ID:HWPSIRT-2026-49982) This vulnerability has bee

    扩展字段
    {
      "hw_psirt_ids": [
        "HWPSIRT-2026-49982"
      ],
      "language": "en",
      "sasn_no": "huawei-sa-SBICVViSHP-38377160",
      "sasn_version": "1.2",
      "severity": "Critical",
      "vulnerabilities": [
        {
          "cveId": "CVE-2026-40974",
          "hwPsirtId": "HWPSIRT-2026-49982"
        }
      ]
    }
    华为安全公告 Critical cve official_bulletin
  • Netty Improper Input Validation Vulnerability in Some Huawei Products

    发布时间 2026-07-22 08:00 (UTC+08:00) 抓取时间 2026-07-22 21:42 (UTC+08:00)

    The open-source software Netty used by some Huawei products has an improper input validation vulnerability. Successful exploitation of this vulnerability may lead to security issues such as DNS cache poisoning and domain validation bypass. (Vulnerability ID:HWPSIRT-2026-68521) This vulnerability has been assigned a Common Vulnerabilities and Exposures (CVE)

    扩展字段
    {
      "hw_psirt_ids": [
        "HWPSIRT-2026-68521"
      ],
      "language": "en",
      "sasn_no": "huawei-sa-NIIVViSHP-22439167",
      "sasn_version": "1.4",
      "severity": "Critical",
      "vulnerabilities": [
        {
          "cveId": "CVE-2026-42579",
          "hwPsirtId": "HWPSIRT-2026-68521"
        }
      ]
    }
    华为安全公告 Critical cve official_bulletin
  • Netty HTTP Smuggling Vulnerability in Some Huawei Products

    发布时间 2026-07-22 08:00 (UTC+08:00) 抓取时间 2026-07-22 21:42 (UTC+08:00)

    The Netty network application framework used by some Huawei products has a smuggling vulnerability in the HTTP client codec module. The vulnerability is caused by a flaw in the logic for pairing HTTP responses with requests. Successful exploitation could lead to incorrect pairing of HEAD requests with 200 responses, affecting the integrity and availability o

    扩展字段
    {
      "hw_psirt_ids": [
        "HWPSIRT-2026-84260"
      ],
      "language": "en",
      "sasn_no": "huawei-sa-NHSViSHP-59875411",
      "sasn_version": "1.4",
      "severity": "Critical",
      "vulnerabilities": [
        {
          "cveId": "CVE-2026-42584",
          "hwPsirtId": "HWPSIRT-2026-84260"
        }
      ]
    }
    华为安全公告 Critical cve official_bulletin