CVE-2016-10138 describes a critical vulnerability in the Shanghai Adups software present on BLU Advance 5.0 and BLU R1 HD devices. The com.adups.fota.sysoper app, installed as a system app, executes with system user privileges and contains an exported broadcast receiver (WriteCommandReceiver) that any app can interact with. This allows a malicious third-party app to execute arbitrary commands, including factory resets, screen recording, and app installation, with elevated privileges. Rated 7.8 HIGH on CVSS, the vulnerability has a low attack complexity and no user interaction required, leading to high impacts on confidentiality, integrity, and availability. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered significant community discussion and media coverage, highlighting its potential for misuse.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:adups:adups_fota:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.