Vulnerabilities > Zteusa > ZTE Zmax Champ Firmware > High

DATE CVE VULNERABILITY TITLE RISK
2018-12-28 CVE-2018-15005 Missing Authorization vulnerability in Zteusa ZTE Zmax Champ Firmware 5.0.3
The ZTE ZMAX Champ Android device with a build fingerprint of ZTE/Z917VL/fortune:6.0.1/MMB29M/20170327.120922:user/release-keys contains a pre-installed platform app with a package name of com.zte.zdm.sdm (versionCode=31, versionName=V5.0.3) that contains an exported broadcast receiver app component named com.zte.zdm.VdmcBroadcastReceiver that allows any app co-located on the device to programmatically initiate a factory reset.
local
low complexity
zteusa CWE-862
7.1