VYPR
Unrated severityNVD Advisory· Published Jun 4, 2019· Updated Aug 4, 2024

CVE-2019-5297

CVE-2019-5297

Description

Emily-L29C Huawei phones versions earlier than 9.0.0.159 (C185E2R1P12T8) have a Factory Reset Protection (FRP) bypass security vulnerability. Before the FRP account is verified and activated during the reset process, the attacker can perform some special operations to bypass the FRP function and obtain the right to use the mobile phone.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Factory Reset Protection bypass on Huawei Emily-L29C phones before 9.0.0.159 allows physical attacker to gain device access.

Vulnerability

A Factory Reset Protection (FRP) bypass vulnerability exists in Huawei Emily-L29C smartphones running versions earlier than 9.0.0.159 (C185E2R1P12T8) [1]. The flaw resides in the FRP implementation: before the FRP account is verified and activated during the reset process, an attacker can perform special operations to bypass the FRP function [1].

Exploitation

An attacker requires physical access to the device during the factory reset process. By executing a sequence of special operations (not publicly detailed) before the FRP account verification completes, the attacker can circumvent the FRP lock [1]. No authentication or network access is needed.

Impact

Successful exploitation allows the attacker to bypass the FRP function and obtain full rights to use the mobile phone, effectively gaining unauthorized access to the device and its data [1].

Mitigation

Huawei has released a software update to fix this vulnerability. Users should upgrade their Emily-L29C devices to version 9.0.0.159 (C185E2R1P12T8) or later [1]. No workarounds are provided in the advisory.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • Huawei/Emily-L29Cllm-create2 versions
    <9.0.0.159 (C185E2R1P12T8)+ 1 more
    • (no CPE)range: <9.0.0.159 (C185E2R1P12T8)
    • (no CPE)range: Version Earlier Than 9.0.0.159(C185E2R1P12T8)

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.