CVE-2019-15389 affects the Haier A6 Android device, stemming from a pre-installed app (com.lovelyfont.defcontainer) that allows arbitrary command execution as the system user. This vulnerability, rated 8.1 HIGH (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H), can be exploited locally by a zero-permission app or remotely via a Man-in-the-Middle (MITM) attack due to insecure network requests. Successful exploitation grants an attacker extensive control, including screen recording, factory resets, and access to sensitive user data like text messages and notifications. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:haier_a6_project:haier_a6_firmware:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.