Android based smartphones from vendors such as Ulefone and Krüger&Matz contain "com.pri.factorytest" application preloaded onto devices during manufacturing process.
The application "com.pri.factorytest" (version name: 1.0, version code: 1) exposes a ”com.pri.factorytest.emmc.FactoryResetService“ service allowing any application to perform a factory reset of the device.
Application update did not increment the APK version. Instead, it was bundled in OS builds released later than December 2024 (Ulefone) and April 2025 (Krüger&Matz).
CVSS
No CVSS.
References
Link | Resource |
---|---|
https://cert.pl/en/posts/2025/05/CVE-2024-13915 |
Configurations
No configuration.
History
10 Jun 2025, 09:15
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
|
Summary | (en) Android based smartphones from vendors such as Ulefone and Krüger&Matz contain "com.pri.factorytest" application preloaded onto devices during manufacturing process. The application "com.pri.factorytest" (version name: 1.0, version code: 1) exposes a ”com.pri.factorytest.emmc.FactoryResetService“ service allowing any application to perform a factory reset of the device. Application update did not increment the APK version. Instead, it was bundled in OS builds released later than December 2024 (Ulefone) and April 2025 (Krüger&Matz). |
30 May 2025, 16:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-05-30 16:15
Updated : 2025-06-10 09:15
NVD link : CVE-2024-13915
Mitre link : CVE-2024-13915
CVE.ORG link : CVE-2024-13915
JSON object : View
Products Affected
No product.
CWE
CWE-926
Improper Export of Android Application Components