Junglewise Threat Intelligence

CVE-2026-41975: Huawei HarmonyOS permission management vulnerability in network module

CVE-2026-41975 · Severity: medium · CVSS 6.3 · Published 2026-06-09

Technologies: Huawei Harmonyos. Vendors: Huawei.

Executive brief

A security vulnerability exists in the network management component of Huawei HarmonyOS, which is used in smartphones, tablets, and PCs. If exploited, this flaw could allow an attacker to compromise the integrity of system services. This could lead to unauthorized changes to network settings or interference with how the device communicates with other services.

Technical details

A permission management vulnerability (CWE-701) exists in the network management module of Huawei HarmonyOS versions 6.0.0 and 6.1.0. The vulnerability is classified as a design-level weakness in how permissions are handled. An attacker with local access and low privileges could exploit this flaw, though it requires high complexity and user interaction (as indicated by the CVSS vector AV:L/AC:H/PR:L/UI:R). Successful exploitation allows the attacker to impact service integrity and confidentiality. Huawei has addressed this issue in the June 2026 security update.

Affected products

  • Huawei HarmonyOS 6.0.0, 6.1.0

Timeline

  • 2026-06-05: patched: Huawei released security bulletins for phones, tablets, and PCs.
  • 2026-06-09: disclosed: NVD published the CVE record.

References

Related threats