CVE-2026-28540
EUVD-2026-980105.03.2026, 08:15
Out-of-bounds character read vulnerability in Bluetooth. Impact: Successful exploitation of this vulnerability may affect service confidentiality.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| huawei | harmonyos | 5.1.0 |
| huawei | harmonyos | 6.0.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-158 - Improper Neutralization of Null Byte or NUL CharacterThe software receives input from an upstream component, but it does not neutralize or incorrectly neutralizes NUL characters or null bytes when they are sent to a downstream component.
- CWE-125 - Out-of-bounds ReadThe software reads data past the end, or before the beginning, of the intended buffer.