CVE-2019-13406: Advan VD-1 has a vulnerability that allows remote arbitrary APK installation
Published Aug 29, 2019
·Updated
A broken access control vulnerability found in Advan VD-1 firmware versions up to 230. An attacker can send a POST request to cgibin/ApkUpload.cgi to install arbitrary APK without any authentication.
Affected Software
2 affected components
Androvideo Vd 1 Firmware<=230
Androvideo Vd 1
Event History
Aug 29, 2019
CVE Published
via MITRE·12:19 AM
Data Sourced
via MITRE·12:19 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2019-13406?
CVE-2019-13406 is classified as a critical vulnerability due to its potential for unauthorized APK installations.
2
How do I fix CVE-2019-13406?
To fix CVE-2019-13406, upgrade the Advan VD-1 firmware to version 231 or later, which addresses this vulnerability.
3
What type of vulnerability is CVE-2019-13406?
CVE-2019-13406 is a broken access control vulnerability that allows attackers to install arbitrary APKs.
4
Which versions of Advan VD-1 are affected by CVE-2019-13406?
Firmware versions up to 230 of the Advan VD-1 are affected by CVE-2019-13406.
5
What could an attacker achieve by exploiting CVE-2019-13406?
An attacker exploiting CVE-2019-13406 can install malicious applications on the device without authentication.