TIT-AL00 smartphones with software versions earlier before TIT-AL00C583B214 have a exposed system interface vulnerability. The software provides a system interface for interaction with external applications, but calling the interface is not properly restricted. An attacker could trick the user into installing a malicious application to call the interface and modify the system properties.
The product provides an Applications Programming Interface (API) or similar interface for interaction with external actors, but the interface includes a dangerous method or function that is not properly restricted.
Link | Tags |
---|---|
http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20170329-01-smartphone-en | vendor advisory |
http://www.securityfocus.com/bid/97224 | vdb entry third party advisory |