CVE-2017-8173 describes a Factory Reset Protection (FRP) bypass vulnerability affecting specific Huawei smartphone models running older software versions. An attacker can exploit this by using a secret code during the re-configuration flow to update the Google account, thereby bypassing the FRP function. This vulnerability has a CVSS v3.0 score of 4.6 (Medium), indicating a physical attack vector with low complexity, no user interaction, and a high impact on integrity. There is no evidence of active exploitation, publicly available exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< maya-l02c636b126CPE matchmatch criteria | cpe:2.3:o:huawei:maya-l02_firmware:*:*:*:*:*:*:*:* | ||
< vky-l29c10b151CPE matchmatch criteria | cpe:2.3:o:huawei:vky-l09_firmware:*:*:*:*:*:*:*:* | ||
< vtr-l29c10b151CPE matchmatch criteria | cpe:2.3:o:huawei:vky-l29_firmware:*:*:*:*:*:*:*:* | ||
< vicky-al00ac00b162CPE matchmatch criteria | cpe:2.3:o:huawei:vicky-al00a_firmware:*:*:*:*:*:*:*:* | ||
< victoria-al00ac00b167CPE matchmatch criteria | cpe:2.3:o:huawei:victoria-al00a_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.