HIGH
Certain software builds for the Nokia C200 and Nokia C100 Android devices contain a vulnerable, pre-installed app with a package name of com.tracfone.tfstatus (versionCode='31', versionName='12') that allows local third-party apps to execute arbitrary AT commands in its context (radio user) via AT command injection due to inadequate access control and inadequate input filtering
Published Apr 22, 2024
7.3
HIGHCVSS 3.1
EPSS 0.78%
Description
Affected products
Remediation
References (1)
Change history (0)
No recorded changes yet.