PT-2018-12864 · Google+1 · Android+1
Published
2018-12-28
·
Updated
2019-02-15
·
CVE-2018-14988
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
MXQ TV Box version 4.4.2
Description
The Android framework in the MXQ TV Box contains an exported broadcast receiver application component that can make the device inoperable when called. The vulnerable component, com.android.server.SystemRestoreReceiver, writes a specific value to the /cache/recovery/command file and boots into recovery mode, resulting in the system partition being formatted or modified and the device being unable to boot properly. This issue can be triggered by any app co-located on the device without requiring any permission. The device may be recoverable by flashing clean firmware images.
Recommendations
For MXQ TV Box version 4.4.2, as a temporary workaround, consider disabling the com.android.server.SystemRestoreReceiver broadcast receiver component until a patch is available. To fully resolve the issue, the user can try flashing clean firmware images placed on an SD card.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Android
Mxq Tv Box