CVE-2018-7936
published 2018-09-04CVE-2018-7936: Mate 10 Pro Huawei smart phones with the versions before BLA-L29 8.0.0.148(C432) have a Factory Reset Protection (FRP) bypass security vulnerability. When…
PriorityP417medium4.6CVSS 3.0
AVPACLPRNUINSUCNIHAN
EPSS
0.24%
14.6th percentile
Mate 10 Pro Huawei smart phones with the versions before BLA-L29 8.0.0.148(C432) have a Factory Reset Protection (FRP) bypass security vulnerability. When re-configuring the mobile phone using the factory reset protection (FRP) function, an attacker can connect the phone with PC and send special instructions to install third party desktop and disable the boot wizard. As a result, the FRP function is bypassed.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| huawei | mate_10_pro_firmware | < bla-l29_8.0.0.148\(c432\) | bla-l29_8.0.0.148\(c432\) |
| huawei_technologies_co_ltd | mate_10_pro | — | — |
CVSS provenance
nvdv3.04.6MEDIUMCVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.04.9MEDIUMAV:L/AC:L/Au:N/C:N/I:C/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2018-09-04
Published