CVE Vulnerabilities

CVE-2025-48904

Authentication Bypass Using an Alternate Path or Channel

Published: Jun 06, 2025 | Modified: Jul 11, 2025
CVSS 3.x
6.2
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Vulnerability that cards can call unauthorized APIs in the FRS process Impact: Successful exploitation of this vulnerability may affect availability.

Weakness

A product requires authentication, but the product has an alternate path or channel that does not require authentication.

Affected Software

Name Vendor Start Version End Version
Harmonyos Huawei 5.0.0 (including) 5.0.0 (including)

Potential Mitigations

References