CVE-2021-41849

MEDIUM

Bluproducts G90 Firmware - Information Disclosure

Title source: rule
STIX 2.1

Description

An issue was discovered in Luna Simo PPR1.180610.011/202001031830. It sends the following Personally Identifiable Information (PII) in plaintext using HTTP to servers located in China: user's list of installed apps and device International Mobile Equipment Identity (IMEI). This PII is transmitted to log.skyroam.com.cn using HTTP, independent of whether the user uses the Simo software.

References (4)

Core 4
Core References
Vendor Advisory x_refsource_misc
https://simowireless.com/
Third Party Advisory x_refsource_misc
https://athack.com/session-details/401

Scores

CVSS v3 5.5
EPSS 0.0025
EPSS Percentile 15.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-319 CWE-200
Status published
Products (5)
bluproducts/g90_firmware
bluproducts/g9_firmware
luna/simo_firmware
wikomobile/tommy_3_firmware
wikomobile/tommy_3_plus_firmware
Published Mar 11, 2022
Tracked Since Feb 18, 2026