CVE-2019-15027
CRITICALMediaTek MT65xx MT66xx MT8163 eMMC Subsystem - OS Command Injection via Filename in Meta Mode Boot
Title source: llmDescription
The MediaTek Embedded Multimedia Card (eMMC) subsystem for Android on MT65xx, MT66xx, and MT8163 SoC devices allows attackers to execute arbitrary commands as root via shell metacharacters in a filename under /data, because clear_emmc_nomedia_entry in platform/mt6577/external/meta/emmc/meta_clr_emmc.c invokes 'system("/system/bin/rm -r /data/' followed by this filename upon an eMMC clearance from a Meta Mode boot. NOTE: compromise of Fire OS on the Amazon Echo Dot would require a second hypothetical vulnerability that allows creation of the required file under /data.
References (2)
Core 2
Core References
Exploit, Third Party Advisory x_refsource_misc
https://dojo.bullguard.com/dojo-by-bullguard/blog/gaining-rooting-primitives-for-android-mediatek-chips/
Scores
CVSS v3
9.8
EPSS
0.0236
EPSS Percentile
85.1%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-78
Status
published
Products (3)
mediatek/mt6577_firmware
mediatek/mt6625_firmware
mediatek/mt8163_firmware
Published
Aug 14, 2019
Tracked Since
Feb 18, 2026