PT-2018-12864 · Google+1 · Android+1

Published

2018-12-28

·

Updated

2019-02-15

·

CVE-2018-14988

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions MXQ TV Box version 4.4.2
Description The Android framework in the MXQ TV Box contains an exported broadcast receiver application component that can make the device inoperable when called. The vulnerable component, com.android.server.SystemRestoreReceiver, writes a specific value to the /cache/recovery/command file and boots into recovery mode, resulting in the system partition being formatted or modified and the device being unable to boot properly. This issue can be triggered by any app co-located on the device without requiring any permission. The device may be recoverable by flashing clean firmware images.
Recommendations For MXQ TV Box version 4.4.2, as a temporary workaround, consider disabling the com.android.server.SystemRestoreReceiver broadcast receiver component until a patch is available. To fully resolve the issue, the user can try flashing clean firmware images placed on an SD card.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-14988

Affected Products

Android
Mxq Tv Box