Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A 2019 analysis of Huawei enterprise-networking firmware reported risky access paths and vulnerabilities, but it did not establish that Huawei deliberately planted backdoors. The findings were summarized by SecurityWeek from an assessment by Finite State; they are historical study results, not evidence of the security or patch status of current equipment.

What equipment did the study examine?

SecurityWeek’s June 27, 2019 article by Eduard Kovacs said Finite State used an automated system to analyze nearly 10,000 firmware images covering 558 Huawei products. The product set included routers, enterprise switches, 4G LTE devices, IP phones and blade-chassis controllers. The analysis was about those enterprise-networking products, not every Huawei product category.

The figures below are the counts and descriptions SecurityWeek attributed to Finite State. The accessible article does not provide the full underlying dataset, and the linked Finite State report PDF was unavailable when checked. The figures therefore cannot be independently assessed from that account alone.

What did the analysis report?

SecurityWeek reported these headline results. The units differ: firmware images, devices and firmware instances are not interchangeable, and the article does not provide enough detail to convert one denominator into another.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Reported result Unit and qualification
More than half had at least one potential backdoor Firmware images analyzed
29% had at least one default username and password stored in firmware Tested devices
76 shipped with default root-user passwords Firmware instances
Hardcoded SSH keys were found in 424 Firmware images
An average of 102 known vulnerabilities Per Huawei firmware image, mainly in open-source and third-party components
Nearly 9,000 critical flaws with a CVSS score of 10 Across the tested firmware instances

These are the reported study results, not a count of confirmed intrusions or proof that every affected device was exploitable in a live network. A stored credential or key can create an access risk; whether it can be used depends on the device, its configuration, exposure and other safeguards.

What did the product comparisons show?

Finite State compared Huawei’s CE12800 high-end network switch with the Arista 7280R and Juniper EX4650. As SecurityWeek described it, all three products had vulnerabilities, but the Arista and Juniper devices had fewer issues in that comparison. The report found no hardcoded credentials or encryption keys in the analyzed Arista and Juniper firmware; for the Huawei device, it reported three sets of default credentials and numerous cryptographic keys.

Rank #2
XG-PON/XGS-PON ONU Stick SFP+ Transceiver with 8311, 10G ONU Stick for FTTx Networks, Compatible with Huawei/ZTE/Ubiquiti/Mikrotik
  • XGSPON STICK ONU SFP+ Transceiver support 20 km transmission distance with SMF
  • SFP package with SC APC
  • Support of XGPON/XGS-PON
  • Supports symmetric and asymmetric protocols
  • Support modify PON Serial Number (ONT ID)/Vendor ID/Equipment ID/Logical ONU ID/Logical Password/MAC…..

A separate comparison looked at CE6851 firmware versions v100 and v200. SecurityWeek said the newer v200 version had more known vulnerabilities and exposed cryptographic keys. The news account does not include the underlying data needed to assess those comparisons independently. They concern selected devices and versions, not every product from these vendors or current firmware releases.

Did the study prove Huawei equipment had deliberately planted backdoors?

No. The phrase “potential backdoors” describes possible access routes or risky components identified by technical analysis; it does not by itself establish deliberate implantation. Finite State founder and CEO Matt Wyckhouse said intent was outside the scope of the technical assessment: “Whether those risks were introduced intentionally or accidentally is out of the scope of a technical assessment, and thus we cannot and do not draw any conclusions relating to intent.”

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

That distinction matters: the findings as reported can indicate security weaknesses worth investigating, but they do not establish who introduced a weakness, why it was present, whether it was exploitable in a particular deployment, or whether it was used.

How did Huawei respond?

SecurityWeek reproduced Huawei’s response in an update to its article. The company said: “We have not and will never implant backdoors. In addition, we will never allow anyone to do so in our equipment.” Huawei also said it was analyzing the report and welcomed further communication with Finite State. This is Huawei’s stated position, not independent verification of the equipment’s security.

Rank #4
LL-XS1010,SC APC,XG-PON/XGS-PON ONU Stick SFP+ Transceiver with 8311, 10G ONU Stick for FTTx Networks, Compatible with Huawei/ZTE/Ubiquiti/Mikrotik
  • XGSPON STICK ONU SFP+ Transceiver support 20 km transmission distance with SMF
  • SFP package with SC APC
  • Support of XGPON/XGS-PON
  • Supports symmetric and asymmetric protocols
  • Support modify PON Serial Number (ONT ID)/Vendor ID/Equipment ID/Logical ONU ID/Logical Password/MAC…..
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What can readers conclude from the report?

The report, as summarized in 2019, raised concerns about credentials, keys and vulnerabilities in the Huawei enterprise firmware it examined. Its reported findings do not settle questions of intent, establish compromise, or describe the state of firmware today. For a specific device, the relevant evidence would be its exact model and firmware version, applicable vendor security advisories and the configuration in which it is deployed.

Best Value
for AVC DATB0625B8F 60mm 48V 4-Pin High Airflow Cooling Fan, 5000RPM, Dual Ball for Huawei Switch, Server, Network Equipment Easy to Replace
  • High-quality fan body: made of high-specification materials, running smoothly and quietly, efficient heat dissipation, and strong durability. ​
  • Fully compatible design: 100% matching the original specifications, adapting to the original machine, and stable operation without debugging. ​
  • Direct replacement: the same specifications, dimensions, and interfaces, easily replace the old fan. ​
  • Factory full inspection: before leaving the factory, it is tested for speed, heat dissipation, etc., 100% up to standard, without hidden troubles. ​
  • Applicable to multiple scenarios: replace aging, abnormal noise, and poor heat dissipation fans to meet the heat dissipation needs of office, games, etc.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.