CVE-2025-54611
HIGHDescription
EXTRA_REFERRER resource read vulnerability in the Gallery module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| huawei | emui |
| huawei | emui |
| huawei | emui |
| huawei | emui |
| huawei | harmonyos |
| huawei | harmonyos |
| huawei | harmonyos |
| huawei | harmonyos |
| huawei | harmonyos |
| huawei | harmonyos |
| huawei | harmonyos |
| huawei | harmonyos |
References
Advisories & Patches
Frequently Asked Questions
What is CVE-2025-54611? +
How severe is CVE-2025-54611? +
What products are affected by CVE-2025-54611? +
How do I check if I'm vulnerable to CVE-2025-54611? +
Related Vulnerabilities
Access control vulnerability in the security verification module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
Service logic error vulnerability in the system service module Impact: Successful exploitation of this vulnerability may affect service integrity.
An issue has been discovered in GitLab EE/CE that could allow an attacker to track users' browsing activities, potentially leading …
Permission bypass vulnerability in the window module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
Status verification vulnerability in the lock screen module. Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.
An S3 bucket takeover vulnerability was identified in the h2oai/h2o-3 repository. The issue involves the S3 bucket 'http://s3.amazonaws.com/h2o-training', which was …