Vulnerabilities > Essential

DATE CVE VULNERABILITY TITLE RISK
2019-04-25 CVE-2018-14994 Improper Input Validation vulnerability in Essential Phone Firmware
The Essential Phone Android device with a build fingerprint of essential/mata/mata:8.1.0/OPM1.180104.166/297:user/release-keys contains a pre-installed platform app with a package name of com.ts.android.hiddenmenu (versionName=1.0, platformBuildVersionName=8.1.0) that contains an exported activity app component named com.ts.android.hiddenmenu.rtn.RTNResetActivity that allows any app co-located on the device to programmatically initiate a factory reset.
network
low complexity
essential CWE-20
7.5