Vulnerabilities > Leagoo > High

DATE CVE VULNERABILITY TITLE RISK
2018-12-28 CVE-2018-14986 Information Exposure vulnerability in Leagoo Z5C Firmware
The Leagoo Z5C Android device with a build fingerprint of sp7731c_1h10_32v4_bird:6.0/MRA58K/android.20170629.214736:user/release-keys contains a pre-installed app with a package name of com.android.messaging (versionCode=1000110, versionName=1.0.001, (android.20170630.092853-0)) containing an exported content provider named com.android.messaging.datamodel.MessagingContentProvider.
network
low complexity
leagoo CWE-200
7.5
2018-12-28 CVE-2018-14985 Missing Authorization vulnerability in Leagoo Z5C Firmware 6.0
The Leagoo Z5C Android device with a build fingerprint of sp7731c_1h10_32v4_bird:6.0/MRA58K/android.20170629.214736:user/release-keys contains a pre-installed platform app with a package name of com.android.settings (versionCode=23, versionName=6.0-android.20170630.092853) that contains an exported broadcast receiver that allows any app co-located on the device to programmatically initiate a factory reset.
local
low complexity
leagoo CWE-862
7.1
2018-12-28 CVE-2018-14984 Information Exposure vulnerability in Leagoo Z5C Firmware
The Leagoo Z5C Android device with a build fingerprint of sp7731c_1h10_32v4_bird:6.0/MRA58K/android.20170629.214736:user/release-keys contains a pre-installed app with a package name of com.android.messaging (versionCode=1000110, versionName=1.0.001, (android.20170630.092853-0)) with an exported broadcast receiver app component named com.android.messaging.trackersender.TrackerSender.
network
low complexity
leagoo CWE-200
7.5
2018-07-13 CVE-2016-6564 Permissions, Privileges, and Access Controls vulnerability in multiple products
Android devices with code from Ragentek contain a privileged binary that performs over-the-air (OTA) update checks.
8.1