Impact
A permission control flaw exists in the web interface of Huawei HarmonyOS, enabling attackers to manipulate access rights and potentially disrupt system operations. The vulnerability is classified as CWE‑362, which covers concurrency control problems that can lead to race conditions. In practice, this flaw could allow an unauthorized user to trigger resource contention or improperly manage permission checks, directly affecting service availability.
Affected Systems
Huawei HarmonyOS is listed as the affected vendor and product. No specific version numbers are provided in the available data, so all builds of HarmonyOS that include the vulnerable web component could be impacted.
Risk and Exploitability
The CVSS score of 8.4 places the vulnerability in the high severity range, indicating significant risk. EPSS data is not available, and the flaw is not yet catalogued in CISA’s KEV list. The likely attack vector is through the web interface, where an attacker may exploit the permission control weakness remotely or from a local authenticated session to cause denial‑of‑service conditions. No additional prerequisites beyond legitimate web access are stated, so the exploitation path appears straightforward but non‑trivial.
OpenCVE Enrichment