Entreprise d'experts en Sécurité Informatique : Audits et conseils en cybersécurité
Entreprise française de cybersécurité depuis 2004
☎ 03 60 47 09 81 - info@securiteinfo.com


CVE-2012-2949

Description

The ZTE sync_agent program for Android 2.3.4 on the Score M device uses a hardcoded ztex1609523 password to control access to commands, which allows remote attackers to gain privileges via a crafted application.

POC

Reference

- http://www.reuters.com/article/2012/05/18/us-zte-phone-idUSBRE84H08J20120518

Github

No PoCs found on GitHub currently.