CVE-2025-48903
Huawei Harmonyos 5.0.0
Raw vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HSummary
CVE-2025-48903 is a high-severity an unspecified weakness vulnerability in Huawei Harmonyos. Its CVSS base score is 7.8 (High).
Operationally, ranked at the 2th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.
The strongest mitigations our analysis identified map to AC-3 (Access Enforcement) and AC-6 (Least Privilege) — see the control section below for these in your framework.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2025-17088
Vulnerability Data
Permission bypass vulnerability in the media library module Impact: Successful exploitation of this vulnerability may affect availability.
- CWE(s)
Related Threats
CVEs Like This One
Affected Assets
Mitigating Controls
Control response
Mitigating Controls (NIST 800-53 r5) AI
Directly enforces access control policy on the media library module, blocking the permission bypass before unauthorized actions succeed.
Limits privileges assigned to the media library module so that even a bypassed permission cannot reach high-impact operations affecting availability.
Provides a tamper-resistant reference monitor that can still mediate every access request to the media library despite flawed permission checks.