On TCL Alcatel Cingular Flip 2 B9HUAH1 devices, there is an undocumented web API that allows unprivileged JavaScript, including JavaScript running within the KaiOS browser, to view and edit the device's firmware over-the-air update settings. (This web API is normally used by the system application to trigger firmware updates via OmaService.js.)
Advisories
Source ID Title
EUVD EUVD EUVD-2019-7050 On TCL Alcatel Cingular Flip 2 B9HUAH1 devices, there is an undocumented web API that allows unprivileged JavaScript, including JavaScript running within the KaiOS browser, to view and edit the device's firmware over-the-air update settings. (This web API is normally used by the system application to trigger firmware updates via OmaService.js.)
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-05T01:10:41.662Z

Reserved: 2019-09-11T00:00:00

Link: CVE-2019-16243

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-11-26T16:15:12.430

Modified: 2024-11-21T04:30:21.810

Link: CVE-2019-16243

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.