Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
On TCL Alcatel Cingular Flip 2 B9HUAH1 devices, there is an undocumented web API that allows unprivileged JavaScript, including JavaScript running within the KaiOS browser, to view and edit the device's firmware over-the-air update settings. (This web API is normally used by the system application to trigger firmware updates via OmaService.js.)
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
TCL Communication Alcatel Cingular Flip 2 B9HUAH1 访问控制错误漏洞
Vulnerability Description
TCL Communication Alcatel Cingular Flip 2 B9HUAH1是中国TCL通讯(TCL Communication)公司的一款手机。 TCL Communication Alcatel Cingular Flip 2 B9HUAH1中存在访问控制错误漏洞,该漏洞源于设备中未被记录的Web API允许运行JavaScript代码,包括在KaiOS浏览器中运行脚本。攻击者可利用该漏洞查看并修改设备固件的无线更新设置。
CVSS Information
N/A
Vulnerability Type
N/A