First published: Fri Mar 11 2022(Updated: )
An issue was discovered in Luna Simo PPR1.180610.011/202001031830. It sends the following Personally Identifiable Information (PII) in plaintext using HTTP to servers located in China: user's list of installed apps and device International Mobile Equipment Identity (IMEI). This PII is transmitted to log.skyroam.com.cn using HTTP, independent of whether the user uses the Simo software.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Bluproducts G90 Firmware | ||
Bluproducts G90 | ||
Bluproducts G9 Firmware | ||
Bluproducts G9 | ||
Wikomobile Tommy 3 Firmware | ||
Wikomobile Tommy 3 | ||
Wikomobile Tommy 3 Plus Firmware | ||
Wikomobile Tommy 3 Plus | ||
Luna Simo Firmware | ||
Luna Simo |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2021-41849 is medium with a CVSS score of 5.5.
Bluproducts G90 Firmware, Bluproducts G9 Firmware, Wikomobile Tommy 3 Firmware, and Luna Simo Firmware are affected by CVE-2021-41849.
CVE-2021-41849 sends Personally Identifiable Information (PII) including the user's list of installed apps and device IMEI in plaintext over HTTP.
No, Bluproducts G90 and Wikomobile Tommy 3 are not vulnerable to CVE-2021-41849.
You can find more information about CVE-2021-41849 at the following references: [https://athack.com/session-details/401](https://athack.com/session-details/401), [https://simowireless.com/](https://simowireless.com/), [https://www.kryptowire.com/android-firmware-2022/](https://www.kryptowire.com/android-firmware-2022/).