CVE-2017-17763 describes a critical vulnerability in SuperBeam through version 4.1.3, specifically impacting its LAN and WiFi Direct Share features. The flaw stems from the application's failure to utilize HTTPS or any integrity-protection mechanisms for file transfers, making it susceptible to crafted file injection, such as APKs. This vulnerability carries a high CVSS score of 7.5, indicating a high potential for impact (confidentiality, integrity, and availability), with a network attack vector and high attack complexity requiring user interaction. While no active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion has been observed, the underlying CWE-311 (Improper Enforcement of Message Integrity) highlights a fundamental security weakness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 4.1.3CPE matchmatch criteria | cpe:2.3:a:liveqos:superbeam:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.2 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.6 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.