cbcvebase.
CVE-2019-19412
published 2020-06-08

CVE-2019-19412: Huawei smart phones have a Factory Reset Protection (FRP) bypass security vulnerability. When re-configuring the mobile phone using the factory reset…

PriorityP418medium4.6CVSS 3.1
AVPACLPRNUINSUCNIHAN
EPSS
0.21%
11.8th percentile
Huawei smart phones have a Factory Reset Protection (FRP) bypass security vulnerability. When re-configuring the mobile phone using the factory reset protection (FRP) function, an attacker login the Talkback mode and can perform some operations to install a third-Party application. Affected products can be found in https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200115-01-frp-en.

Affected

108 ranges· showing 25
VendorProductVersion rangeFixed in
huaweialp-al00b
huaweialp-al00b_firmware< 9.0.0.181\(c00e87r2p20t8\)9.0.0.181\(c00e87r2p20t8\)
huaweialp-l09
huaweialp-l09_firmware< 9.0.0.201\(c432e4r1p9\)9.0.0.201\(c432e4r1p9\)
huaweialp-l29
huaweialp-l29
huaweialp-l29_firmware< 9.0.0.177\(c185e2r1p12t8\)9.0.0.177\(c185e2r1p12t8\)
huaweialp-l29_firmware< 9.0.0.195\(c636e2r1p12\)9.0.0.195\(c636e2r1p12\)
huaweianne-al00
huaweianne-al00_firmware< 8.0.0.168\(c00\)8.0.0.168\(c00\)
huaweiberkeley-al20
huaweiberkeley-al20_firmware< 9.0.0.156\(c00e156r2p14t8\)9.0.0.156\(c00e156r2p14t8\)
huaweiberkeley-l09
huaweiberkeley-l09
huaweiberkeley-l09_firmware< 8.0.0.172\(c432\)8.0.0.172\(c432\)
huaweiberkeley-l09_firmware< 8.0.0.173\(c636\)8.0.0.173\(c636\)
huaweibla-al00b
huaweibla-al00b_firmware< 9.0.0.181\(c00e88r2p15t8\)9.0.0.181\(c00e88r2p15t8\)
huaweibla-l09c
huaweibla-l09c
huaweibla-l09c_firmware< 9.0.0.177\(c185e2r1p13t8\)9.0.0.177\(c185e2r1p13t8\)
huaweibla-l09c_firmware< 9.0.0.206\(c432e4r1p11\)9.0.0.206\(c432e4r1p11\)
huaweibla-l29c
huaweibla-l29c
huaweibla-l29c

CVSS provenance

nvdv3.14.6MEDIUMCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:P/A:N
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.