An improper authentication vulnerability was discovered in the Motorola Factory Test component (com.motorola.motocit). The application contained a reference to a writable file descriptor in external storage which could be used by third party apps running on the device to open a TCP server, exposing sensitive permissions and data. This could allow a local attacker to bypass permission checks and access protected device settings.
Metrics
Affected Vendors & Products
References
History
Tue, 19 May 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 19 May 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Local Permission Escalation via Factory Test Component | |
| Weaknesses | CWE-284 |
Tue, 19 May 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An improper authentication vulnerability was discovered in the Motorola Factory Test component (com.motorola.motocit). The application contained a reference to a writable file descriptor in external storage which could be used by third party apps running on the device to open a TCP server, exposing sensitive permissions and data. This could allow a local attacker to bypass permission checks and access protected device settings. | |
| First Time appeared |
Motorola
Motorola phones |
|
| CPEs | cpe:2.3:a:motorola:phones:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Motorola
Motorola phones |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: lenovo
Published: 2026-05-19T14:42:21.989Z
Updated: 2026-05-19T16:39:42.750Z
Reserved: 2026-04-08T14:38:14.415Z
Link: CVE-2026-5804
Updated: 2026-05-19T16:38:20.549Z
Status : Awaiting Analysis
Published: 2026-05-19T16:16:22.413
Modified: 2026-05-19T17:57:25.143
Link: CVE-2026-5804
No data.