CVE-2017-8161 describes a Factory Reset Protection (FRP) bypass vulnerability affecting specific earlier software versions of Huawei EVA-L09 smartphones. An attacker can exploit this by manipulating the Swype login during FRP re-configuration to update the Google account, thereby bypassing the FRP function. Rated as Medium severity (CVSS 4.6), this vulnerability has a physical attack vector and low complexity, potentially leading to a complete bypass of the FRP security measure. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< eva-l09c25b150custc25d003CPE matchmatch criteria | cpe:2.3:o:huawei:eva-l09:*:*:*:*:*:*:*:* | ||
< eva-l09c440b140CPE matchmatch criteria | cpe:2.3:o:huawei:eva-l09:*:*:*:*:*:*:*:* | ||
< eva-l09c464b361CPE matchmatch criteria | cpe:2.3:o:huawei:eva-l09:*:*:*:*:*:*:*:* | ||
< l09c675b320custc675d004CPE matchmatch criteria | cpe:2.3:o:huawei:eva-l09:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.