Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Huawei

Huawei Vendor Cyber Rating & Cyber Score

huawei.com

Huawei is a leading global provider of information and communications technology (ICT) infrastructure and smart devices. With integrated solutions across four key domains – telecom networks, IT, smart devices, and cloud services – we are committed to bringing digital to every person, home and organization for a fully connected, intelligent world. Huawei's end-to-end portfolio of products, solutions and services are both competitive and secure. Through open collaboration with ecosystem partners, we create lasting value for our customers, working to empower people, enrich home life, and inspire innovation in organizations of all shapes and sizes. At Huawei, innovation focuses on customer needs. We invest heavily in basic research,


Huawei A.I CyberSecurity Scoring

Huawei
Company Information
Website:http://www.huawei.com/en/
Employees number:134,994
Number of followers:5,383,705
NAICS:517
Industry Type:Telecommunications
Homepage:huawei.com
Huawei Risk Score (AI oriented)
Between 750 and 799
logo
HuaweiTelecommunications
Updated:
08/04/2026
799/1000
Fair
Baa
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Huawei Global Score (TPRM)
xxxx
logo
HuaweiTelecommunications
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

Huawei
HuaweiFair
Current Score
799Baa (FAIR)
01000
2 incidents
-32 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
801Before Incident
MAY 2026
800Before Incident
APRIL 2026
799Before Incident
MARCH 2026
799Before Incident
FEBRUARY 2026
798Before Incident
JANUARY 2026
798Before Incident
DECEMBER 2025
797Before Incident
NOVEMBER 2025
796Before Incident
OCTOBER 2025
826Before Incident
Breach
06 Oct 2025Huawei
Huawei Technologies Co., Ltd.

Alleged Breach of Huawei’s Internal Repositories and Source Code Leak

794After Incident
CRITICAL-32
HUA1993019100625
Threat actors have alleged a breach of Huawei’s internal code repositories, claiming to have exfiltrated proprietary source code (including network management software, base station firmware, and security libraries) and development tools. The leaked materials, if verified, expose Huawei’s software architecture, encryption routines, authentication workflows, and potential vulnerabilities, enabling tailored exploits against its global telecommunications infrastructure. The incident heightens geopolitical and national security concerns, particularly for 5G deployments and government networks, as competitors or APT groups could reverse-engineer the code for latent vulnerabilities or sophisticated attacks. While Huawei has not confirmed the breach, the disclosure alone risks eroding trust in its products, potentially leading to delayed approvals, contract revocations, or increased scrutiny from intelligence agencies. Customers are advised to enhance monitoring, patch management, and access controls to mitigate risks from potential zero-day exploits derived from the leak.
INCIDENT DETAILS -
TYPE
Data BreachSource Code LeakUnauthorized Access
MOTIVATION
Financial Gain (sale of source code)Reputation (underground forum credibility)Potential Espionage or Competitive Advantage
IMPACT
Proprietary source codeDevelopment toolsTechnical documentationNetwork management softwareBase station firmwareSecurity librariesHuawei internal repositoriesCode development environmentsPotential downstream telecommunications equipmentPotential erosion of trust in Huawei productsReassessment of risk posture by intelligence agencies and corporate security teamsPossible delays or revocations of Huawei product approvalsHigh (geopolitical and national security concerns amplified)Potential loss of customer confidenceCompetitors may exploit leaked code for reverse-engineering
DATA BREACH
Proprietary source codeTechnical documentationDevelopment toolsSecurity librariesSensitivity Of Data: High (includes encryption routines, authentication workflows, potential vulnerabilities)Data Exfiltration: Alleged (unverified)Source code filesFirmwareDocumentation
SEPTEMBER 2025
826Before Incident
AUGUST 2025
826Before Incident
JULY 2025
826Before Incident
NOVEMBER 2024
832Before Incident
Cyber Attack
01 Nov 2024Huawei
NETGEAR, Huawei, TP-Link and D-Link: Masjesu Botnet Emerges as DDoS-for-Hire Service Targeting Global IoT Devices

Masjesu Botnet: A Stealthy DDoS-for-Hire Threat Expands Its Reach

824After Incident
LOW-8
HUADLITP-NET1775672907
Masjesu Botnet: A Stealthy DDoS-for-Hire Threat Expands Its Reach Cybersecurity researchers have uncovered Masjesu, a sophisticated botnet operating as a DDoS-for-hire service since 2023. Marketed via Telegram under the alias XorBot, the malware targets IoT devices including routers, cameras, and gateways across multiple architectures, employing XOR-based encryption to evade detection. First documented by Chinese security firm NSFOCUS in December 2023 and linked to an operator known as synmaestro, Masjesu has since evolved. A 2024 update introduced 12 new exploits targeting devices from D-Link, Huawei, NETGEAR, TP-Link, and others, alongside enhanced DDoS flood modules. Researchers note its rapid growth, with attackers increasingly leveraging Telegram for recruitment and promotion. Trellix’s recent analysis reveals Masjesu’s focus on volumetric DDoS attacks, particularly against CDNs, game servers, and enterprises. The botnet’s infrastructure is heavily concentrated in Vietnam (nearly 50% of observed traffic), with additional activity in Ukraine, Iran, Brazil, Kenya, and India. Once deployed, the malware establishes persistence, disables competing processes, and connects to command servers to execute attacks. Masjesu also self-propagates by scanning for vulnerable devices, including Realtek routers via port 52869 a tactic previously used by botnets like JenX and Satori. Notably, the botnet avoids high-profile targets like the U.S. Department of Defense to minimize legal scrutiny, prioritizing long-term survival over mass infection. As IoT exploitation expands, Masjesu’s low-visibility approach and social media-driven recruitment underscore its adaptability as a persistent cyber threat.
INCIDENT DETAILS -
TYPE
DDoS-for-Hire Botnet
MOTIVATION
Financial gain (DDoS-for-hire service)Long-term survival with low visibility
IMPACT
IoT devices (routers, cameras, gateways)Disruption of CDNs, game servers, and enterprises via volumetric DDoS attacks
DATA BREACH
Data Encryption: XOR-based encryption

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Huawei ?
?
What was Huawei's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Huawei's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Huawei's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Huawei's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Huawei's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Huawei's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Huawei's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Huawei's A.I Rankiteo Cyber Score in October 2025 ?
?
What was Huawei's A.I Rankiteo Cyber Score in September 2025 ?
?
What was Huawei's A.I Rankiteo Cyber Score in August 2025 ?
?
What was Huawei's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on Huawei's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Huawei ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Huawei's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?