RSS   Vulnerabilities for 'Zenfone v live firmware'   RSS

2019-04-25
 
CVE-2018-14993

CWE-77
 

 
The ASUS Zenfone V Live Android device with a build fingerprint of asus/VZW_ASUS_A009/ASUS_A009:7.1.1/NMF26F/14.0610.1802.78-20180313:user/release-keys and the Asus ZenFone 3 Max Android device with a build fingerprint of asus/US_Phone/ASUS_X008_1:7.0/NRD90M/US_Phone-14.14.1711.92-20171208:user/release-keys both contain a pre-installed platform app with a package name of com.asus.splendidcommandagent (versionCode=1510200090, versionName=1.2.0.18_160928) that contains an exported service named com.asus.splendidcommandagent.SplendidCommandAgentService that allows any app co-located on the device to supply arbitrary commands to be executed as the system user. This app cannot be disabled by the user and the attack can be performed by a zero-permission app. Executing commands as system user can allow a third-party app to video record the user's screen, factory reset the device, obtain the user's notifications, read the logcat logs, inject events in the Graphical User Interface (GUI), change the default Input Method Editor (IME) (e.g., keyboard) with one contained within the attacking app that contains keylogging functionality, obtain the user's text messages, and more.

 

 >>> Vendor: ASUS 84 Products
Video security online
Remote console
Smartlogon
Asus wl-330ge
Asus wl-500w
Rt-n56u firmware
Rt-n56u
Ipswcom activex component
Net4switch
Rt-ac66u
Rt-n14u
Rt-n16u
Rt-n65u
Rt-n66u
Rt-ac66u firmware
Rt-n14u firmware
Rt-n16 firmware
Rt-n65u firmware
Rt-n66u firmware
Rt-n10e
Rt-n10e firmware
Wl-330nul
Rt-ac68u
Rt-ac68u firmware
Rt firmware
Rt series firmware
Wrt firmware
Rt-ac56s
Rt-ac87u
Rt-ac56s firmware
Rt-ac87u firmware
Rt-n10+d1 firmware
Rt-g32 firmware
Tm-1900
Wl-330nul firmware
Wl-33nul firmware
Tm-ac1900 firmware
Rt-ac53 firmware
Rt-ac1750 firmware
Dsl-n10s firmware
Asuswrt
Dsl-ac51 firmware
Dsl-ac52u firmware
Dsl-ac55u firmware
Dsl-ac56u firmware
Dsl-ac750 firmware
Dsl-n10 c1 firmware
Dsl-n12e c1 firmware
Dsl-n12u c1 firmware
Dsl-n14u-b1 firmware
Dsl-n14u firmware
Dsl-n16 firmware
Dsl-n16u firmware
Dsl-n17u firmware
Dsl-n55u c1 firmware
Dsl-n55u d1 firmware
Dsl-n66u firmware
Rt-ac1200 firmware
Rt-ac2900 firmware
Rt-ac51u firmware
Rt-ac52u b1 firmware
Rt-ac55u firmware
Rt-ac55uhp firmware
Rt-ac58u firmware
Rt-ac86u firmware
Rt-acrh13 firmware
Rt-n12 d1 firmware
Rt-n600 firmware
Ea-n66 firmware
Rp-ac52 firmware
Rp-ac56 firmware
Rp-n12 firmware
Rp-n14 firmware
Rp-n53 firmware
Wmp-n12 firmware
Hg100 firmware
Gt-ac5300 firmware
Zenfone 3 max firmware
Aura sync firmware
Zenfone v live firmware
Rt-ac3200 firmware
Smarthome
Precision touchpad
Asuswrt-merlin


Copyright 2019, cxsecurity.com

 

Back to Top