"TITLE":"Advan VD-1 allows a remote user to enable Android Debug Bridge without any authentication"
},
"affects":{
"vendor":{
"vendor_data":[
{
"vendor_name":"AndroVideo",
"product":{
"product_data":[
{
"product_name":"Advan VD-1 firmware",
"version":{
"version_data":[
{
"version_value":"230"
}
]
}
}
]
}
}
]
}
},
"credit":[
{
"lang":"eng",
"value":"Keniver Wang (CHT Security) "
}
],
"data_format":"MITRE",
"data_type":"CVE",
"data_version":"4.0",
"description":{
"description_data":[
{
"lang":"eng",
"value":"A broken access control vulnerability found in Advan VD-1 firmware version 230 leads to insecure ADB service. An attacker can send a POST request to cgibin/AdbSetting.cgi to enable ADB without any authentication then take the compromised device as a relay or to install mining software."