Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2023-38290

EPSS 0.05% · P15
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2023-38290

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
Certain software builds for the BLU View 2 and Sharp Rouvo V Android devices contain a vulnerable pre-installed app with a package name of com.evenwell.fqc (versionCode='9020801', versionName='9.0208.01' ; versionCode='9020913', versionName='9.0209.13' ; versionCode='9021203', versionName='9.0212.03') that allows local third-party apps to execute arbitrary shell commands in its context (system user) due to inadequate access control. No permissions or special privileges are necessary to exploit the vulnerability in the com.evenwell.fqc app. No user interaction is required beyond installing and running a third-party app. The vulnerability allows local apps to access sensitive functionality that is generally restricted to pre-installed apps, such as programmatically performing the following actions: granting arbitrary permissions (which can be used to obtain sensitive user data), installing arbitrary apps, video recording the screen, wiping the device (removing the user's apps and data), injecting arbitrary input events, calling emergency phone numbers, disabling apps, accessing notifications, and much more. The software build fingerprints for each confirmed vulnerable device are as follows: BLU View 2 (BLU/B131DL/B130DL:11/RP1A.200720.011/1672046950:user/release-keys, BLU/B131DL/B130DL:11/RP1A.200720.011/1663816427:user/release-keys, BLU/B131DL/B130DL:11/RP1A.200720.011/1656476696:user/release-keys, BLU/B131DL/B130DL:11/RP1A.200720.011/1647856638:user/release-keys) and Sharp Rouvo V (SHARP/VZW_STTM21VAPP/STTM21VAPP:12/SP1A.210812.016/1KN0_0_460:user/release-keys and SHARP/VZW_STTM21VAPP/STTM21VAPP:12/SP1A.210812.016/1KN0_0_530:user/release-keys). This malicious app starts an exported activity named com.evenwell.fqc/.activity.ClickTest, crashes the com.evenwell.fqc app by sending an empty Intent (i.e., having not extras) to the com.evenwell.fqc/.FQCBroadcastReceiver receiver component, and then it sends command arbitrary shell commands to the com.evenwell.fqc/.FQCService service component which executes them with "system" privileges.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
com.evenwell.fqc 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
com.evenwell.fqc是一个组件。 com.evenwell.fqc存在安全漏洞,该漏洞源于设备的某些软件版本包含易受攻击的预装应用程序(com.evenwell.fqc),允许本地第三方应用程序在其环境中执行任意 shell 命令。以下产品及版本受到影响:Tracfone BLU View 2 、Verizon Sharp Rouvo V。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2023-38290

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2023-38290

登录查看更多情报信息。

Same Patch Batch · n/a · 2024-04-22 · 44 CVEs total

CVE-2023-38301vendor.gsm.serial 安全漏洞
CVE-2023-38302flask-cors 安全漏洞
CVE-2023-38300Verizon Orbic Maui 安全漏洞
CVE-2023-38296TCL 安全漏洞
CVE-2023-38295Tcl 安全漏洞
CVE-2023-38294Itel Vision 3 Turbo 安全漏洞
CVE-2023-38291TCL 20XE和TCL 10L 安全漏洞
CVE-2023-38292TCL 20XE 安全漏洞
CVE-2023-38298TCL 安全漏洞
CVE-2023-38293Nokia C100 安全漏洞
CVE-2023-38299多款产品 安全漏洞
CVE-2022-34561phpFox 跨站脚本漏洞
CVE-2022-34560phpFox 安全漏洞
CVE-2022-34562phpFox 跨站脚本漏洞
CVE-2022-46897编号已被CVE保留
CVE-2022-35503Open Source MANO 安全漏洞
CVE-2024-27574Trainme Academy 安全漏洞
CVE-2024-29661Desdev DedeCMS 安全漏洞
CVE-2024-29368moziloCMS 安全漏洞
CVE-2024-29376Sylius 安全漏洞

Showing top 20 of 44 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2023-38290

No comments yet


Leave a comment