PT-2019-14595 · Tcl+1 · Tcl Alcatel Cingular Flip 2+1
Publicado
2019-11-26
·
Atualizado
2020-08-24
·
CVE-2019-16243
CVSS v3.1
6.1
Média
| Vetor | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
TCL Alcatel Cingular Flip 2 version B9HUAH1
Description
The issue concerns an undocumented web API that permits unprivileged JavaScript, including JavaScript running within the KaiOS browser, to view and edit the device's firmware over-the-air update settings. This web API is typically used by the system application to trigger firmware updates via OmaService.js.
Recommendations
For version B9HUAH1, as a temporary workaround, consider restricting access to the undocumented web API until a patch is available. Avoid using the OmaService.js for firmware updates until the issue is resolved.
Exploit
Correção
Missing Authentication
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Kaios
Tcl Alcatel Cingular Flip 2