Vulnerabilities > Plum Mobile

DATE CVE VULNERABILITY TITLE RISK
2019-04-25 CVE-2018-14989 Improper Input Validation vulnerability in Plum-Mobile Compass Firmware
The Plum Compass Android device with a build fingerprint of PLUM/c179_hwf_221/c179_hwf_221:6.0/MRA58K/W16.51.5-22:user/release-keys contains a pre-installed platform app with a package name of com.android.settings (versionCode=23, versionName=6.0-eng.root.20161223.224055) that contains an exported broadcast receiver app component which allows any app co-located on the device to programmatically perform a factory reset.
network
low complexity
plum-mobile CWE-20
critical
9.4