VYPR
Unrated severityNVD Advisory· Published Nov 14, 2019· Updated Aug 5, 2024

CVE-2019-15414

CVE-2019-15414

Description

A pre-installed Asus ZenFone AR app with command execution capability can be abused by other pre-installed apps via exposed components.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A pre-installed Asus ZenFone AR app with command execution capability can be abused by other pre-installed apps via exposed components.

Vulnerability

The Asus ZenFone AR (build fingerprint asus/WW_ASUS_A002/ASUS_A002:7.0/NRD90M/14.1600.1805.51-20180626:user/release-keys) contains a pre-installed app with package name com.asus.splendidcommandagent (versionCode=1510200105, versionName=1.2.0.21_180605). This app exposes an accessible component that allows command execution. The vulnerability is reachable by any other pre-installed app on the device that can obtain signatureOrSystem permissions, which are required by other pre-installed apps that export their capabilities [1].

Exploitation

An attacker would need to have a pre-installed app on the device that can acquire signatureOrSystem permissions. No additional user interaction is required because the malicious pre-installed app can directly access the exposed component of com.asus.splendidcommandagent to execute arbitrary commands on the device. The exact sequence involves invoking the accessible component within the target app to perform command execution with system privileges [1].

Impact

Successful exploitation allows the attacker to execute arbitrary commands on the device with the privileges of the com.asus.splendidcommandagent app, which likely runs with system-level permissions. This leads to full compromise of the device's integrity and confidentiality, including potential data theft, installation of additional payloads, or modification of system settings [1].

Mitigation

As of the publication date (2019-11-14), the available reference does not disclose a specific fix or patched version. Users are advised to remove or disable the pre-installed app if possible, or to obtain an updated firmware from Asus that addresses this issue. No CISA KEV listing was identified [1].

References
  1. Home

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • Asus/ZenFone ARdescription
  • Asus/ZenFone ARllm-create
    Range: 7.0 NRD90M / build fingerprint asus/WW_ASUS_A002/ASUS_A002:7.0/NRD90M/14.1600.1805.51-20180626:user/release-keys

Patches

0

No patches discovered yet.

Vulnerability mechanics

No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.

References

1

News mentions

0

No linked articles in our index yet.