VYPR
Unrated severityNVD Advisory· Published Aug 29, 2019· Updated Sep 16, 2024

Advan VD-1 has a vulnerability that allows remote arbitrary APK installation

CVE-2019-13406

Description

A broken access control vulnerability found in Advan VD-1 firmware versions up to 230. An attacker can send a POST request to cgibin/ApkUpload.cgi to install arbitrary APK without any authentication.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Adv VD-1 ≤v230 allows unauthenticated arbitrary APK install via POST to cgibin/ApkUpload.cgi.

Vulnerability

CVE-2019-13406 is a missing authentication vulnerability in the Advan VD-1 firmware up to version 230. The endpoint cgibin/ApkUpload.cgi accepts POST requests without any access control, allowing an attacker to upload and install arbitrary APK files on the device. The vulnerability affects AndroVideo Advan VD-1 (firmware ≤ v230), as confirmed by the advisory [1].

Exploitation

An attacker only needs network access to the device. No authentication is required. By sending a crafted POST request to cgibin/ApkUpload.cgi with an arbitrary APK payload, the attacker can cause the device to install the uploaded application [1].

Impact

Successful exploitation allows an attacker to install arbitrary Android applications (APKs) on the VD-1 device. This can lead to installation of malware, backdoors, or mining software, effectively giving the attacker persistent control over the device and potentially enabling further compromise of the local network [1].

Mitigation

The vendor has not released a patch for this vulnerability as of the publication date. Users should restrict network access to the device to trusted networks only and consider isolating it until an official firmware update is available. The affected versions are Advan VD-1 firmware ≤ v230; devices running a newer version are not mentioned in the advisory [1].

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • Advan/VD-1llm-fuzzy
    Range: <=230
  • AndroVideo/Advan VD-1 firmwarev5
    Range: up to 230

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.