PT-2025-29906 · Unknown · Bluebird Devices

Szymon Chadam

·

Published

2025-07-17

·

Updated

2025-07-17

·

CVE-2025-5345

CVSS v4.0

6.3

Medium

VectorAV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N
Name of the Vulnerable Software and Affected Versions Bluebird devices version 1.4.4 Bluebird devices version 1.3.6
Description Bluebird devices contain a pre-loaded file manager application that exposes an unsecured service provider com.bluebird.system.koreanpost.IsdcardRemoteService. A local attacker can bind to the AIDL-type service to copy and delete arbitrary files from the device's storage with system-level permissions.
Recommendations Update Bluebird devices from version 1.4.4 to a newer, non-vulnerable version. Revert Bluebird devices from version 1.4.4 to version 1.3.6.

Fix

Weakness Enumeration

Related Identifiers

CVE-2025-5345

Affected Products

Bluebird Devices