CVE-2017-17161 describes an authentication bypass vulnerability in the "Find Phone" function of specific Huawei Duke-L09 smartphone models running software versions earlier than Duke-L09C10B186, Duke-L09C432B187, or Duke-L09C636B186. This flaw, stemming from improper authentication, allows an attacker to bypass the "Find Phone" function and regain normal use of the device. Rated 6.8 MEDIUM on CVSSv3, it has a physical attack vector (AV:P) and low attack complexity (AC:L), with high impacts on confidentiality, integrity, and availability (C:H/I:H/A:H). There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< duke-l09c10b186CPE matchmatch criteria | cpe:2.3:o:huawei:duke-l09_firmware:*:*:*:*:*:*:*:* | ||
< duke-l09c432b187CPE matchmatch criteria | cpe:2.3:o:huawei:duke-l09_firmware:*:*:*:*:*:*:*:* | ||
< duke-l09c636b186CPE matchmatch criteria | cpe:2.3:o:huawei:duke-l09_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.