CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

huawei

fusioncompute

17 known vulnerabilities · sorted by CVSS score

CVE-2020-9233
CRITICAL9.1

FusionCompute 8.0.0 have an insufficient authentication vulnerability. An attacker may exploit the vulnerability to delete some files and cause some services abnormal.

huawei / fusioncompute
Network
Published Aug 17, 2020
CVE-2020-9236
HIGH8.8

There is an improper interface design vulnerability in Huawei product. A module interface of the impated product does not deal with some operations properly. Attackers can exploit this vulnerability to perform malicious operatation to compromise module service. (Vulnerability ID: HWPSIRT-2020-05010) This vulnerability has been assigned a Common Vulnerabilities and Exposures (CVE) ID: CVE-2020-9236.

huawei / fusioncompute
Network
Published Dec 27, 2024
CVE-2021-37102
HIGH8.8

There is a command injection vulnerability in CMA service module of FusionCompute product when processing the default certificate file. The software constructs part of a command using external special input from users, but the software does not sufficiently validate the user input. Successful exploit could allow the attacker to inject certain commands to the system. Affected product versions include: FusionCompute 6.0.0, 6.3.0, 6.3.1, 6.5.0, 6.5.1, 8.0.0.

huawei / fusioncompute+5
Network
Published Nov 23, 2021
CVE-2020-9242
HIGH8.8

FusionCompute 8.0.0 have a command injection vulnerability. The software does not sufficiently validate certain parameters post from user, successful exploit could allow an authenticated attacker to launch a command injection attack.

huawei / fusioncompute
Network
Published Aug 17, 2020
CVE-2020-9078
HIGH7.8

FusionCompute 8.0.0 have local privilege escalation vulnerability. A local, authenticated attacker could perform specific operations to exploit this vulnerability. Successful exploitation may cause the attacker to obtain a higher privilege and compromise the service.

huawei / fusioncompute
Local
Published Aug 10, 2020
CVE-2020-9114
HIGH7.8

FusionCompute versions 6.3.0, 6.3.1, 6.5.0, 6.5.1 and 8.0.0 have a privilege escalation vulnerability. Due to improper privilege management, an attacker with common privilege may access some specific files and get the administrator privilege in the affected products. Successful exploit will cause privilege escalation.

huawei / fusioncompute+4
Local
Published Dec 1, 2020
CVE-2021-37105
HIGH7.5

There is an improper file upload control vulnerability in FusionCompute 6.5.0, 6.5.1 and 8.0.0. Due to the improper verification of file to be uploaded and does not strictly restrict the file access path, attackers may upload malicious files to the device, resulting in the service abnormal.

huawei / fusioncompute+2
Network
Published Sep 28, 2021
CVE-2020-9228
HIGH7.5

FusionCompute 8.0.0 has an information disclosure vulnerability. Due to the properly protection of certain information, attackers may exploit this vulnerability to obtain certain information.

huawei / fusioncompute
Network
Published Aug 14, 2020
CVE-2020-9116
HIGH7.2

Huawei FusionCompute versions 6.5.1 and 8.0.0 have a command injection vulnerability. An authenticated, remote attacker can craft specific request to exploit this vulnerability. Due to insufficient verification, this could be exploited to cause the attackers to obtain higher privilege.

huawei / fusioncompute+1
Network
Published Dec 1, 2020
CVE-2021-37106
HIGH7.2

There is a command injection vulnerability in CMA service module of FusionCompute 6.3.0, 6.3.1, 6.5.0 and 8.0.0 when processing the default certificate file. The software constructs part of a command using external special input from users, but the software does not sufficiently validate the user input. Successful exploit could allow the attacker to inject certain commands to the system.

huawei / fusioncompute+3
Network
Published Sep 28, 2021
CVE-2020-9222
HIGH7.0

There is a privilege escalation vulnerability in Huawei FusionCompute product. Due to insufficient verification on specific files that need to be deserialized, local attackers can exploit this vulnerability to elevate permissions. (Vulnerability ID: HWPSIRT-2020-05241) This vulnerability has been assigned a Common Vulnerabilities and Exposures (CVE) ID: CVE-2020-9222.

huawei / fusioncompute+4
Local
Published Dec 27, 2024
CVE-2020-9248
MEDIUM6.7

Huawei FusionComput 8.0.0 have an improper authorization vulnerability. A module does not verify some input correctly and authorizes files with incorrect access. Attackers can exploit this vulnerability to launch privilege escalation attack. This can compromise normal service.

huawei / fusioncompute
Local
Published Jul 31, 2020
CVE-2020-9246
MEDIUM6.5

FusionCompute 8.0.0 has an information leak vulnerability. A module does not launch strict access control and information protection. Attackers with low privilege can get some extra information. This can lead to information leak.

huawei / fusioncompute
Network
Published Aug 21, 2020
CVE-2021-37036
MEDIUM5.5

There is an information leakage vulnerability in FusionCompute 6.5.1, eCNS280_TD V100R005C00 and V100R005C10. Due to the improperly storage of specific information in the log file, the attacker can obtain the information when a user logs in to the device. Successful exploit may cause the information leak.

huawei / ecns280_td_firmware+2
Local
Published Nov 23, 2021
CVE-2020-9229
MEDIUM4.4

FusionCompute 8.0.0 has an information disclosure vulnerability. Due to the properly protection of certain information, attackers may exploit this vulnerability to obtain certain information.

huawei / fusioncompute
Local
Published Aug 14, 2020
CVE-2020-9128
MEDIUM4.4

FusionCompute versions 8.0.0 have an insecure encryption algorithm vulnerability. Attackers with high permissions can exploit this vulnerability to cause information leak.

huawei / fusioncompute
Local
Published Nov 12, 2020
CVE-2021-22358
MEDIUM4.3

There is an insufficient input validation vulnerability in FusionCompute 8.0.0. Due to the input validation is insufficient, an attacker can exploit this vulnerability to upload any files to the device. Successful exploit may cause the service abnormal.

huawei / fusioncompute
Network
Published May 27, 2021