CVE-2023-25647: Permission and Access Control Vulnerability in Some ZTE Mobile Phones
Published Aug 17, 2023
·Updated
There is a permission and access control vulnerability in some ZTE mobile phones. Due to improper access control, applications in mobile phone could monitor the touch event.
Affected Software
8 affected components
ZTE Axon 30 Firmware<3.0.0b06
ZTE Axon 30
ZTE Axon 40 Pro Firmware<1.0.0b16
ZTE Axon 40 Pro
ZTE Axon 40 Ultra Firmware<2.0.0b17
ZTE Axon 40 Ultra
ZTE Nubia Z50 Firmware<1.0.0b19mr
ZTE Nubia Z50
Event History
Aug 17, 2023
CVE Published
via MITRE·02:13 AM
Data Sourced
via MITRE·02:13 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2023-25647?
CVE-2023-25647 is a permission and access control vulnerability found in some ZTE mobile phones.
2
How does CVE-2023-25647 affect ZTE Axon 30 Firmware?
CVE-2023-25647 affects ZTE Axon 30 Firmware up to version 3.0.0b06.
3
Is ZTE Axon 30 affected by CVE-2023-25647?
No, ZTE Axon 30 is not affected by CVE-2023-25647.
4
What is the severity of CVE-2023-25647?
CVE-2023-25647 has a severity rating of 3.3 (medium).
5
How can I fix CVE-2023-25647 in ZTE Axon 30 Firmware?
To fix CVE-2023-25647 in ZTE Axon 30 Firmware, update to a version beyond 3.0.0b06.