Huawei today acknowledged a vulnerability affecting devices using its HiSilicon-branded video surveillance chips that could allow an attacker backdoor access.

The admission comes after security researcher Vladislav Yarmak published a report detailing the vulnerability on Habr, a Russian IT and computer science blog. It allows an attacker to activate the affected device's Telnet service, which is disabled by default, using transmission control protocol (TCP) port 9530. Once activated, the attacker can obtain the password from the device firmware or gain access using brute force.

Vulnerable devices include digital and network video recorders and IP cameras from a variety of original equipment manufacturers (OEM) using HiSilicon surveillance chips. According to Yarmak, the impacted devices appear to be limited to those running software from China-based surveillance vendor Xiongmai.

Nearly a year ago, Huawei Rotating Chairman Guo Ping took to the stage at MWC Barcelona and claimed the company had not, and would never plant backdoors or allow anyone to do so to its equipment. However, it appears the telecom giant may have done just that. Whether or not the backdoor was intentionally planted or not remains unclear.

Huawei maintains that the vulnerability was not introduced by its HiSilicon chips or software development kit. Instead, Huawei placed blame on OEMs which it said failed to remove the Telnet service, used for debugging, from the HiSilicon reference code before shipping commercial products.

Huawei warned HiSilicon customers to remove Telnet and other functions that could pose a security risk. The company added that the Telnet function has been removed from all Huawei-branded equipment using its HiSilicon chip.

Further, the company said it is willing to work with equipment vendors and researchers to address the vulnerability and protect end users.

Huawei Warns of Data Authenticity Vulnerability

Huawei also published a security advisory today warning that some of its products have an "insufficient verification of data authenticity vulnerability."

The vulnerability could enable a remote, unauthenticated attacker to intercept and modify packets sent between two devices. Huawei has not detailed which devices are affected and has since released software updates to resolve this vulnerability.