CVE-2019-16241 is a medium-severity vulnerability affecting TCL Alcatel Cingular Flip 2 devices that allows for PIN authentication bypass. An attacker with physical access can create a specific file via Android Debug Bridge (adb) over USB, which the lock screen application then interprets as a signal to disable PIN authentication. This grants full access to the device's data and functionality. The vulnerability has a CVSS score of 6.8 (Medium), indicating a low attack complexity but high impact on confidentiality, integrity, and availability. While it requires physical proximity (AV:P), no user interaction is needed (UI:N). There is no evidence of active exploitation, publicly available exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
b9huah1CPE matchmatch criteria | cpe:2.3:o:alcatelmobile:cingular_flip_2_firmware:b9huah1:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.