CVE-2024-10576CWE-925

Unauthorized factory reset of Infinix devices

Critical · published December 4, 2024

CVSS v4.0
9.4
EPSS
0%
Percentile
5.9
In the wild
Unconfirmed
What it is

Infinix devices contain a pre-loaded "com.transsion.agingfunction" application, that exposes an unsecured broadcast receiver. An attacker can communicate with the receiver and force the device to perform a factory reset without any Android system permissions.

After multiple attempts to contact the vendor we did not receive any answer. We suppose this issue affects all Infinix Mobile devices.

The record
Technical detail
CVSS v4.0
9.4 · CRITICAL
Vector
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/S:N/R:I/V:D/U:Amber
EPSS
0.00164 · 5.9th percentile
Weakness
CWE-925 · Improper Verification of Intent by Broadcast Receiver
Published
2024-12-04T12:02Z
EPSS history
Timeline
  • 04 DEC 12:02Z
    Unauthorized factory reset of Infinix devices
    cvelistv5