PT-2018-18361 · Huawei · Huawei Mate 10

Rongwei Ji

·

Published

2018-09-18

·

Updated

2019-10-03

·

CVE-2018-7991

CVSS v3.1

4.6

Medium

VectorAV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions: Huawei Mate10 versions earlier than 8.0.0.110(C00)
Description: The issue concerns a Factory Reset Protection (FRP) bypass. It arises because the system does not sufficiently verify permissions. An attacker can exploit this by connecting the smartphone to a computer using a data cable and performing specific operations. This could allow the attacker to bypass FRP protection and access the system setting page.
Recommendations: For versions earlier than 8.0.0.110(C00), update to version 8.0.0.110(C00) or later to resolve the issue. As a temporary workaround, consider restricting physical access to the device to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2018-7991

Affected Products

Huawei Mate 10