VYPR
Unrated severityNVD Advisory· Published Nov 14, 2019· Updated Aug 5, 2024

CVE-2019-15420

CVE-2019-15420

Description

The Blackview BV9000Pro-F Android device with a build fingerprint of Blackview/BV9000Pro-F/BV9000Pro-F:7.1.1/N4F26M/1514363110:user/release-keys contains a pre-installed app with a package name of com.mediatek.factorymode app (versionCode=1, versionName=1) that allows unauthorized wireless settings modification via a confused deputy attack. This capability can be accessed by any app co-located on the device.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

The Blackview BV9000Pro-F Android device includes a pre-installed factory mode app that enables any app to modify wireless settings via a confused deputy attack.

Vulnerability

The Blackview BV9000Pro-F (build fingerprint Blackview/BV9000Pro-F/BV9000Pro-F:7.1.1/N4F26M/1514363110:user/release-keys) contains a pre-installed app with package name com.mediatek.factorymode (versionCode=1, versionName=1) that exposes a functionality to modify wireless settings. Due to a confused deputy attack, any co-located app can invoke this capability without proper authorization [1].

Exploitation

An attacker needs to have any app installed on the device (no special permissions required). The malicious app can send an intent or use the exposed interface of the factory mode app to change wireless settings, such as Wi-Fi or Bluetooth configurations. No user interaction is required beyond installation of the malicious app.

Impact

A successful exploit allows an unprivileged app to modify wireless settings on the device, potentially leading to denial of service by disabling connectivity, or man-in-the-middle attacks by changing Wi-Fi configurations. The attacker does not gain elevated privileges beyond the ability to change wireless settings.

Mitigation

As of the publication date (2019-11-14), no official fix has been released by Blackview. The device may be end-of-life or not receiving updates. Users should avoid installing untrusted apps and consider using a firewall or permissions manager to restrict the factory mode app's accessible activities.

References
  1. Home

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.