VYPR
Unrated severityNVD Advisory· Published Nov 14, 2019· Updated Aug 5, 2024

CVE-2019-15423

CVE-2019-15423

Description

The Bluboo Bluboo_S1 Android device with a build fingerprint of BLUBOO/Bluboo_S1/Bluboo_S1:7.0/NRD90M/1495809471:user/release-keys contains a pre-installed app with a package name of com.mediatek.factorymode app (versionCode=1, versionName=1) that allows unauthorized wireless settings modification via a confused deputy attack. This capability can be accessed by any app co-located on the device.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A pre-installed FactoryMode app on the Bluboo S1 allows any co-located app to modify wireless settings via a confused deputy attack.

Vulnerability

The Bluboo Bluboo_S1 Android device (build fingerprint BLUBOO/Bluboo_S1/Bluboo_S1:7.0/NRD90M/1495809471:user/release-keys) includes a pre-installed application with the package name com.mediatek.factorymode (versionCode=1, versionName=1) that exposes functionality to modify wireless settings. Due to a confused deputy design weakness, this capability can be invoked by any third-party application installed on the same device without requiring any special permissions from the calling app [1].

Exploitation

An attacker needs only to have any app co-located on the device (no root access, no user interaction beyond installing the malicious app). The malicious app can directly invoke the factory-mode app's exported components to change Wi‑Fi or other wireless configurations without the user's knowledge or consent [1].

Impact

A successful attack allows the unauthorized modification of wireless settings on the device. This could enable an attacker to redirect network traffic, connect to malicious access points, or degrade wireless connectivity — ultimately compromising the confidentiality and integrity of data transmitted over the device's network connections [1].

Mitigation

No official fix or updated firmware has been identified in the available references. The only effective mitigation is to avoid installing untrusted applications on the device or to remove or disable the com.mediatek.factorymode app if possible via ADB or device management tools [1].

References
  1. Home

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.