CVE-2019-15410
Description
Pre-installed app on Asus ZenFone 5Q allows other pre-installed apps to execute arbitrary commands via an exposed component, enabling privilege escalation.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Pre-installed app on Asus ZenFone 5Q allows other pre-installed apps to execute arbitrary commands via an exposed component, enabling privilege escalation.
Vulnerability
A pre-installed app with package name com.asus.loguploaderproxy (versionCode=1570000020, versionName=7.0.0.4_170901) on Asus ZenFone 5Q devices (build fingerprint asus/WW_Phone/ASUS_X017D_2:7.1.1/NGI77B/14.0400.1809.059-20181016:user/release-keys) exposes an accessible component that allows other pre-installed apps to perform command execution. This component is reachable by any pre-installed app on the device that can obtain signatureOrSystem permissions, which are required by other pre-installed apps that export their capabilities [1].
Exploitation
An attacker needs to have a pre-installed app on the device that can acquire signatureOrSystem permissions. Such an app can then invoke the exposed component of com.asus.loguploaderproxy to execute arbitrary commands. No user interaction is required beyond the device running the affected software [1].
Impact
Successful exploitation allows the attacker to execute arbitrary commands with system privileges, leading to full compromise of the device's confidentiality, integrity, and availability [1].
Mitigation
No patch has been publicly released by Asus as of the publication date. The only mitigation is to remove or disable the pre-installed app if possible, though this may require root access. Users should keep the device updated for any future firmware fixes [1].
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Asus/ZenFone 5Qdescription
- Range: Android 7.1.1 with build NGI77B / firmware 14.0400.1809.059-20181016
Patches
0No patches discovered yet.
Vulnerability mechanics
No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.
References
1- www.kryptowire.com/android-firmware-2019/mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.