Impact
The vulnerability is a permission control flaw in Huawei HarmonyOS’s smart sensing service; it is identified as a value‑based access control issue (CWE‑840). If successfully exploited, an attacker could read data handled by the service, thereby compromising the confidentiality of that data.
Affected Systems
Huawei HarmonyOS devices that include the smart sensing service are affected. No specific firmware versions or product editions are mentioned, so all HarmonyOS releases containing the smart sensing service may be at risk.
Risk and Exploitability
The CVSS base score of 5.6 indicates medium severity. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting no widely known exploit at the time of analysis. Because the attack vector is not explicitly stated, it is inferred that an attacker might need either local access or the ability to invoke the smart sensing service through an application. The overall risk is moderate with an undefined likelihood of exploitation pending further intelligence.
OpenCVE Enrichment