Advan VD-1 has a vulnerability that allows remote arbitrary APK installation
Description
A broken access control vulnerability found in Advan VD-1 firmware versions up to 230. An attacker can send a POST request to cgibin/ApkUpload.cgi to install arbitrary APK without any authentication.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Adv VD-1 ≤v230 allows unauthenticated arbitrary APK install via POST to cgibin/ApkUpload.cgi.
Vulnerability
CVE-2019-13406 is a missing authentication vulnerability in the Advan VD-1 firmware up to version 230. The endpoint cgibin/ApkUpload.cgi accepts POST requests without any access control, allowing an attacker to upload and install arbitrary APK files on the device. The vulnerability affects AndroVideo Advan VD-1 (firmware ≤ v230), as confirmed by the advisory [1].
Exploitation
An attacker only needs network access to the device. No authentication is required. By sending a crafted POST request to cgibin/ApkUpload.cgi with an arbitrary APK payload, the attacker can cause the device to install the uploaded application [1].
Impact
Successful exploitation allows an attacker to install arbitrary Android applications (APKs) on the VD-1 device. This can lead to installation of malware, backdoors, or mining software, effectively giving the attacker persistent control over the device and potentially enabling further compromise of the local network [1].
Mitigation
The vendor has not released a patch for this vulnerability as of the publication date. Users should restrict network access to the device to trusted networks only and consider isolating it until an official firmware update is available. The affected versions are Advan VD-1 firmware ≤ v230; devices running a newer version are not mentioned in the advisory [1].
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- AndroVideo/Advan VD-1 firmwarev5Range: up to 230
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- surl.twcert.org.tw/hVut7mitrex_refsource_CONFIRM
- gist.github.com/keniver/f5155b42eb278ec0273b83565b64235bmitrex_refsource_CONFIRM
- tvn.twcert.org.tw/taiwanvn/TVN-201906007mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.