Permission Control Vulnerability in Huawei Gallery Module
CVE-2025-54654

6.2MEDIUM

Key Information:

Vendor

Huawei

Status
Vendor
CVE Published:
11 October 2025

What is CVE-2025-54654?

A permission control vulnerability has been identified in the Gallery module developed by Huawei. This flaw enables unauthorized access to sensitive information, potentially compromising the confidentiality of services. If exploited, the vulnerability could allow attackers to manipulate data access permissions, resulting in privacy violations and unauthorized disclosures of user data. It is crucial for users and administrators to evaluate their affected systems and implement the necessary security measures to mitigate the risks associated with this vulnerability.

Affected Version(s)

HarmonyOS 5.1.0

HarmonyOS 5.0.1

References

CVSS V3.1

Score:
6.2
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-54654 : Permission Control Vulnerability in Huawei Gallery Module