CVE-2011-4872 describes a vulnerability in multiple HTC Android devices, including the Desire HD, Sensation, and EVO models. A crafted application with the ACCESS_WIFI_STATE permission could exploit a weakness in the WifiConfiguration.toString method to remotely obtain 802.1X Wi-Fi credentials and SSID. This vulnerability has a low CVSS score of 2.6, indicating a partial confidentiality impact with high attack complexity and no authentication required. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
frg83dCPE matchmatch criteria | cpe:2.3:h:htc:desire_hd:frg83d:*:*:*:*:*:*:* | ||
gri40CPE matchmatch criteria | cpe:2.3:h:htc:desire_hd:gri40:*:*:*:*:*:*:* | ||
gri40CPE matchmatch criteria | cpe:2.3:h:htc:desire_s:gri40:*:*:*:*:*:*:* | ||
frf91CPE matchmatch criteria | cpe:2.3:h:htc:droid_incredible:frf91:*:*:*:*:*:*:* | ||
gri40CPE matchmatch criteria | cpe:2.3:h:htc:evo_3d:gri40:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:H/Au:N/C:P/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.