CVE-2019-15420
Description
The Blackview BV9000Pro-F Android device with a build fingerprint of Blackview/BV9000Pro-F/BV9000Pro-F:7.1.1/N4F26M/1514363110:user/release-keys contains a pre-installed app with a package name of com.mediatek.factorymode app (versionCode=1, versionName=1) that allows unauthorized wireless settings modification via a confused deputy attack. This capability can be accessed by any app co-located on the device.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
The Blackview BV9000Pro-F Android device includes a pre-installed factory mode app that enables any app to modify wireless settings via a confused deputy attack.
Vulnerability
The Blackview BV9000Pro-F (build fingerprint Blackview/BV9000Pro-F/BV9000Pro-F:7.1.1/N4F26M/1514363110:user/release-keys) contains a pre-installed app with package name com.mediatek.factorymode (versionCode=1, versionName=1) that exposes a functionality to modify wireless settings. Due to a confused deputy attack, any co-located app can invoke this capability without proper authorization [1].
Exploitation
An attacker needs to have any app installed on the device (no special permissions required). The malicious app can send an intent or use the exposed interface of the factory mode app to change wireless settings, such as Wi-Fi or Bluetooth configurations. No user interaction is required beyond installation of the malicious app.
Impact
A successful exploit allows an unprivileged app to modify wireless settings on the device, potentially leading to denial of service by disabling connectivity, or man-in-the-middle attacks by changing Wi-Fi configurations. The attacker does not gain elevated privileges beyond the ability to change wireless settings.
Mitigation
As of the publication date (2019-11-14), no official fix has been released by Blackview. The device may be end-of-life or not receiving updates. Users should avoid installing untrusted apps and consider using a firewall or permissions manager to restrict the factory mode app's accessible activities.
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Blackview/BV9000Pro-Fdescription
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- www.kryptowire.com/android-firmware-2019/mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.