CVE-2019-15426: Low severity mi 5s plus vulnerability
The Xiaomi 5S Plus Android device with a build fingerprint of Xiaomi/natrium/natrium:6.0.1/MXB48T/7.1.5:user/release-keys contains a pre-installed app with a package name of com.miui.powerkeeper app (versionCode=40000, versionName=4.0.00) that allows unauthorized wireless settings modification via a confused deputy attack. This capability can be accessed by any app co-located on the device.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability description of CVE-2019-15426?
CVE-2019-15426 describes a pre-installed app on the Xiaomi 5S Plus that allows unauthorized modification of wireless settings.
What is the severity of CVE-2019-15426?
The severity of CVE-2019-15426 is not explicitly assigned, but it poses a significant security risk due to unauthorized access.
How do I fix CVE-2019-15426?
To mitigate CVE-2019-15426, update the affected Xiaomi 5S Plus device to the latest firmware version provided by the manufacturer.
Which devices are affected by CVE-2019-15426?
CVE-2019-15426 specifically affects the Xiaomi 5S Plus running certain versions of Android with the app com.miui.powerkeeper.
What impact does CVE-2019-15426 have on users?
CVE-2019-15426 can potentially allow attackers to alter network settings without user consent, compromising device security.