CVE-2018-14995 affects several ZTE Blade and ZMAX Android devices, where a pre-installed modem service app exposes an interface allowing any app to enable and access sensitive modem and system-wide logcat logs. These logs can contain phone numbers, full text messages, and call details. The vulnerability has a medium CVSS score of 4.7, indicating a local attack vector with high complexity, requiring an attacker to have local access and the READ_EXTERNAL_STORAGE permission to exfiltrate data. While the logs are inactive by default, a third-party app can activate them. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
7.1.1CPE matchmatch criteria | cpe:2.3:o:zteusa:zte_blade_vantage_firmware:7.1.1:*:*:*:*:*:*:* | ||
7.1.1CPE matchmatch criteria | cpe:2.3:o:zteusa:zte_blade_spark_firmware:7.1.1:*:*:*:*:*:*:* | ||
6.0.1CPE matchmatch criteria | cpe:2.3:o:zteusa:zte_zmax_pro_firmware:6.0.1:*:*:*:*:*:*:* | ||
6.0.1CPE matchmatch criteria | cpe:2.3:o:zteusa:zte_zmax_champ_firmware:6.0.1:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.4 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.