CVE-2018-7988

Severity
4.6MEDIUM
EPSS
0.0%
top 93.33%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 27
Latest updateMay 13

Description

There is a Factory Reset Protection (FRP) bypass vulnerability on several smartphones. The system does not sufficiently verify the permission, an attacker uses a data cable to connect the smartphone to another smartphone and then perform a series of specific operations. Successful exploit could allow the attacker bypass the FRP protection.

CVSS vector

CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:NExploitability: 0.9 | Impact: 3.6

Affected Packages2 packages

NVDhuawei/mate_9_pro_firmware< 8.0.0.363\(c00\)
NVDhuawei/nova_2_plus_firmware< 8.0.0.350\(c00\)

🔴Vulnerability Details

2
GHSA
GHSA-xmm3-954r-xwww: There is a Factory Reset Protection (FRP) bypass vulnerability on several smartphones2022-05-13
CVEList
CVE-2018-7988: There is a Factory Reset Protection (FRP) bypass vulnerability on several smartphones2018-11-27

💥Exploits & PoCs

1
Exploit-DB
WolfSight CMS 3.2 - SQL Injection2018-07-10
CVE-2018-7988 (MEDIUM CVSS 4.6) | There is a Factory Reset Protection | cvebase.io