CVE Feed

    Dashboard / CVE / CVE-2016-6564

    CVE-2016-6564

    Android devices with code from Ragentek contain a privileged binary that performs over-the-air (OTA) update checks. Additionally, there are multiple techniques used to hide the execution of this binary. This behavior could be described as a rootkit. This binary, which resides as /system/bin/debugs, runs with root privileges and does not communicate over an encrypted channel. The binary has been shown to communicate with three hosts via HTTP: oyag[.]lhzbdvm[.]com oyag[.]prugskh[.]net oyag[.]prugskh[.]com Server responses to requests sent by the debugs binary include functionalities to execute arbitrary commands as root, install applications, or update configurations. Examples of a request sent by the client binary: POST /pagt/agent?data={"name":"c_regist","details":{...}} HTTP/1. 1 Host: 114.80.68.223 Connection: Close An example response from the server could be: HTTP/1.1 200 OK {"code": "01", "name": "push_commands", "details": {"server_id": "1" , "title": "Test Command", "comments": "Test", "commands": "touch /tmp/test"}} This binary is reported to be present in the following devices: BLU Studio G BLU Studio G Plus BLU Studio 6.0 HD BLU Studio X BLU Studio X Plus BLU Studio C HD Infinix Hot X507 Infinix Hot 2 X510 Infinix Zero X506 Infinix Zero 2 X509 DOOGEE Voyager 2 DG310 LEAGOO Lead 5 LEAGOO Lead 6 LEAGOO Lead 3i LEAGOO Lead 2S LEAGOO Alfa 6 IKU Colorful K45i Beeline Pro 2 XOLO Cube 5.0

    Published:Jul 13, 2018
    Last Modified:Nov 21, 2024
    EPS:Jul 13, 2018
    EPSS Score:0.00428
    CVSS Score:8.1

    Affected Products

    Vendor
    Beeline
    Product
    Pro 2
    Vendor
    Beeline
    Product
    Pro 2 Firmware
    Vendor
    Bluproducts
    Product
    Studio 6.0 Hd
    Vendor
    Bluproducts
    Product
    Studio 6.0 Hd Firmware
    Vendor
    Bluproducts
    Product
    Studio C Hd
    Vendor
    Bluproducts
    Product
    Studio C Hd Firmware
    Vendor
    Bluproducts
    Product
    Studio G
    Vendor
    Bluproducts
    Product
    Studio G Firmware
    Vendor
    Bluproducts
    Product
    Studio G Plus
    Vendor
    Bluproducts
    Product
    Studio G Plus Firmware
    Vendor
    Bluproducts
    Product
    Studio X
    Vendor
    Bluproducts
    Product
    Studio X Firmware
    Vendor
    Bluproducts
    Product
    Studio X Plus
    Vendor
    Bluproducts
    Product
    Studio X Plus Firmware
    Vendor
    Doogee
    Product
    Voyager 2 Dg310i
    Vendor
    Doogee
    Product
    Voyager 2 Dg310i Firmware
    Vendor
    Iku-mobile
    Product
    Colorful K45i
    Vendor
    Iku-mobile
    Product
    Colorful K45i Firmware
    Vendor
    Infinixauthority
    Product
    Hot 2 X510
    Vendor
    Infinixauthority
    Product
    Hot 2 X510 Firmware
    Vendor
    Infinixauthority
    Product
    Hot X507
    Vendor
    Infinixauthority
    Product
    Hot X507 Firmware
    Vendor
    Infinixauthority
    Product
    Zero 2 X509
    Vendor
    Infinixauthority
    Product
    Zero 2 X509 Firmware
    Vendor
    Infinixauthority
    Product
    Zero X506
    Vendor
    Infinixauthority
    Product
    Zero X506 Firmware
    Vendor
    Leagoo
    Product
    Alfa 6
    Vendor
    Leagoo
    Product
    Alfa 6 Firmware
    Vendor
    Leagoo
    Product
    Lead 2s
    Vendor
    Leagoo
    Product
    Lead 2s Firmware
    Vendor
    Leagoo
    Product
    Lead 3i
    Vendor
    Leagoo
    Product
    Lead 3i Firmware
    Vendor
    Leagoo
    Product
    Lead 5
    Vendor
    Leagoo
    Product
    Lead 5 Firmware
    Vendor
    Leagoo
    Product
    Lead 6
    Vendor
    Leagoo
    Product
    Lead 6 Firmware
    Vendor
    Xolo
    Product
    Cube 5.0
    Vendor
    Xolo
    Product
    Cube 5.0 Firmware

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High