VYPR
Unrated severityNVD Advisory· Published Nov 29, 2019· Updated Aug 4, 2024

CVE-2019-5308

CVE-2019-5308

Description

Mate 20 RS smartphones with versions earlier than 9.1.0.135(C786E133R3P1) have an improper authorization vulnerability. The software does not properly restrict certain operation in ADB mode, successful exploit could allow the attacker to switch to third desktop after a series of operation.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Improper authorization in ADB mode on Huawei Mate 20 RS allows an attacker to switch to a third-party desktop, bypassing security restrictions.

Vulnerability

An improper authorization vulnerability exists in Huawei Mate 20 RS smartphones running versions earlier than 9.1.0.135(C786E133R3P1) [1]. The software fails to properly restrict certain operations when the device is in Android Debug Bridge (ADB) mode. This allows an attacker to perform actions that should be unauthorized, specifically the ability to switch to a third desktop environment.

Exploitation

To exploit this vulnerability, an attacker must have access to the device while it is in ADB mode, typically requiring a USB connection and ADB debugging enabled. The attacker then executes a series of operations (likely ADB commands) to trigger the unauthorized switch to a third desktop [1]. No authentication is needed beyond the ADB connection, but physical or USB access to the device is required.

Impact

Successful exploitation allows the attacker to switch the device's desktop environment to a third-party launcher or desktop. This could bypass security controls enforced by the default desktop, potentially enabling further unauthorized actions or access to sensitive data. The impact is limited to changing the desktop, but it may serve as a stepping stone for more severe attacks.

Mitigation

Huawei has released a software update to fix this vulnerability. Users should upgrade their Mate 20 RS to version 9.1.0.135(C786E133R3P1) or later [1]. No workarounds are provided in the advisory. The vulnerability is not listed on the CISA Known Exploited Vulnerabilities (KEV) catalog as of the publication date.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • Huawei/Mate 20 RS smartphonesdescription
  • Huawei/Mate 20 RSllm-create
    Range: <9.1.0.135(C786E133R3P1)

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.