CVE-2025-66319
Huawei Harmonyos 5.1.0 … 6.0.0
Raw vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:LSummary
CVE-2025-66319 is a low-severity an unspecified weakness vulnerability in Huawei Harmonyos. Its CVSS base score is 3.3 (Low).
Operationally, ranked at the 1th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.
The strongest mitigations our analysis identified map to AC-3 (Access Enforcement) and AC-6 (Least Privilege) — see the control section below for these in your framework.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2025-208310
Vulnerability Data
Permission control vulnerability in the resource scheduling module. Impact: Successful exploitation of this vulnerability may affect service integrity.
- CWE(s)
Related Threats
MITRE ATT&CK Enterprise TechniquesAI
Insufficient information to map techniques.CVEs Like This One
Affected Assets
Mitigating Controls
Control response
Mitigating Controls (NIST 800-53 r5) AI
Directly enforces access decisions to block unauthorized permission use in the resource scheduling module.
Limits privileges assigned to the scheduling module so exploitation cannot alter service integrity.
Enforces information flow rules that would constrain unauthorized resource scheduling actions.