PT-2018-12867 · Leagoo+1 · Leagoo P1+1

Publicado

2018-12-28

·

Atualizado

2019-10-03

·

CVE-2018-14998

CVSS v2.0

7.2

Alta

VetorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Leagoo P1 Android device with a build fingerprint of sp7731c 1h10 32v4 bird:6.0/MRA58K/android.20170629.214736:user/release-keys
Description The issue allows for command execution as the root user due to a hidden root privilege escalation capability. A user with physical access to the device can obtain a root shell via ADB by modifying read-only system properties at runtime, specifically the ro.debuggable and the ro.secure system properties, and then restarting the ADB daemon.
Recommendations For the Leagoo P1 Android device with the specified build fingerprint, consider restricting physical access to the device to minimize the risk of exploitation. As a temporary workaround, avoid modifying the ro.debuggable and ro.secure system properties to prevent potential root shell access via ADB. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

OS Command Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-14998

Produtos afetados

Android
Leagoo P1