CVE-2025-31710

MEDIUM

EngineerMode Service - Command Injection

Title source: llm

Description

In engineermode service, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed.

Exploits (1)

nomisec WORKING POC 86 stars
by Skorpion96 · poc
https://github.com/Skorpion96/unisoc-su

Scores

CVSS v3 5.9
EPSS 0.0003
EPSS Percentile 7.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

Details

CWE
CWE-77
Status published
Products (3)
google/android 13.0
google/android 14.0
google/android 15.0
Published Jun 03, 2025
Tracked Since Feb 18, 2026