CVE Vulnerabilities

CVE-2025-54646

Improper Handling of Length Parameter Inconsistency

Published: Aug 06, 2025 | Modified: Aug 13, 2025
CVSS 3.x
4.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Vulnerability of inadequate packet length check in the BLE module. Impact: Successful exploitation of this vulnerability may affect performance.

Weakness

The product parses a formatted message or structure, but it does not handle or incorrectly handles a length field that is inconsistent with the actual length of the associated data.

Affected Software

NameVendorStart VersionEnd Version
EmuiHuawei12.0.0 (including)12.0.0 (including)
EmuiHuawei13.0.0 (including)13.0.0 (including)
EmuiHuawei14.0.0 (including)14.0.0 (including)
HarmonyosHuawei2.0.0 (including)2.0.0 (including)
HarmonyosHuawei2.1.0 (including)2.1.0 (including)
HarmonyosHuawei3.0.0 (including)3.0.0 (including)
HarmonyosHuawei3.1.0 (including)3.1.0 (including)
HarmonyosHuawei4.0.0 (including)4.0.0 (including)
HarmonyosHuawei4.2.0 (including)4.2.0 (including)
HarmonyosHuawei4.3.0 (including)4.3.0 (including)
HarmonyosHuawei5.0.1 (including)5.0.1 (including)
HarmonyosHuawei5.1.0 (including)5.1.0 (including)

Potential Mitigations

References