CVE-2016-10138
An issue was discovered on BLU Advance 5.0 and BLU R1 HD devices with Shanghai Adups software. The com.adups.fota.sysoper app is installed as a system app and cannot be disabled by the user. In the com.adups.fota.sysoper app's AndroidManifest.xml file, it sets the android:sharedUserId attribute to a value of android.uid.system which makes it execute as the system user, which is a very privileged user on the device. The app has an exported broadcast receiver named com.adups.fota.sysoper.WriteCommandReceiver which any app on the device can interact with.
Leer descripción completaMostrar menos
Therefore, any app can send a command embedded in an intent which will be executed by the WriteCommandReceiver component which is executing as the system user. The third-party app, utilizing the WriteCommandReceiver, can perform the following actions: call a phone number, factory reset the device, take pictures of the screen, record the screen in a video, install applications, inject events, obtain the Android log, and others. In addition, the com.adups.fota.sysoper.TaskService component will make a request to a URL of http://rebootv5.adsunflower.com/ps/fetch.do where the commands in the String array with a key of sf in the JSON Object sent back by the server will be executed as the system user. Since the connection is made via HTTP, it is vulnerable to a MITM attack.
CVSS
- Versión: 3.0
- Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 7.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.38%
- Percentil entre todas las CVEs puntuadas: 30
- Fecha de la puntuación: 3/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-310
Referencias
- http://www.securityfocus.com/bid/96853
- https://www.kryptowire.com/adups_security_analysis.html
- https://www.nytimes.com/2016/11/16/us/politics/china-phones-software-security.html
- http://www.securityfocus.com/bid/96853
- https://www.kryptowire.com/adups_security_analysis.html
- https://www.nytimes.com/2016/11/16/us/politics/china-phones-software-security.html
JSON original (NVD)
Mostrar
{
"id": "CVE-2016-10138",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 7.2,
"accessVector": "LOCAL",
"vectorString": "AV:L/AC:L/Au:N/C:C/I:C/A:C",
"authentication": "NONE",
"integrityImpact": "COMPLETE",
"accessComplexity": "LOW",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": true,
"impactScore": 10,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 3.9,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV30": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.0",
"baseScore": 7.8,
"attackVector": "LOCAL",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 1.8
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2017-01-13T09:59:00.263",
"references": [
{
"url": "http://www.securityfocus.com/bid/96853",
"source": "cve@mitre.org"
},
{
"url": "https://www.kryptowire.com/adups_security_analysis.html",
"tags": [
"Technical Description",
"Third Party Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://www.nytimes.com/2016/11/16/us/politics/china-phones-software-security.html",
"tags": [
"Press/Media Coverage"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/96853",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.kryptowire.com/adups_security_analysis.html",
"tags": [
"Technical Description",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.nytimes.com/2016/11/16/us/politics/china-phones-software-security.html",
"tags": [
"Press/Media Coverage"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-310"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "An issue was discovered on BLU Advance 5.0 and BLU R1 HD devices with Shanghai Adups software. The com.adups.fota.sysoper app is installed as a system app and cannot be disabled by the user. In the com.adups.fota.sysoper app's AndroidManifest.xml file, it sets the android:sharedUserId attribute to a value of android.uid.system which makes it execute as the system user, which is a very privileged user on the device. The app has an exported broadcast receiver named com.adups.fota.sysoper.WriteCommandReceiver which any app on the device can interact with. Therefore, any app can send a command embedded in an intent which will be executed by the WriteCommandReceiver component which is executing as the system user. The third-party app, utilizing the WriteCommandReceiver, can perform the following actions: call a phone number, factory reset the device, take pictures of the screen, record the screen in a video, install applications, inject events, obtain the Android log, and others. In addition, the com.adups.fota.sysoper.TaskService component will make a request to a URL of http://rebootv5.adsunflower.com/ps/fetch.do where the commands in the String array with a key of sf in the JSON Object sent back by the server will be executed as the system user. Since the connection is made via HTTP, it is vulnerable to a MITM attack."
},
{
"lang": "es",
"value": "Se descubrió un problema en los dispositivos BLU Advance 5.0 y BLU R1 HD con software Shanghai Adups. La aplicación com.adups.fota.sysoper está instalada como una aplicación del sistema y no puede ser deshabilitada por el usuario. En el archivo AndroidManifest.xml de la aplicación com.adups.fota.sysoper, establece el atributo android: sharedUserId en un valor de android.uid.system que lo hace ejecutar como el usuario del sistema, el cual es un usuario muy privilegiado en el dispositivo. La aplicación tiene un receptor de difusión exportado llamado com.adups.fota.sysoper.WriteCommandReceiver con el que cualquier aplicación del dispositivo puede interactuar. Por lo tanto, cualquier aplicación puede enviar un comando incrustado en un intento que será ejecutado por el componente WriteCommandReceiver que se está ejecutando como usuario del sistema. La aplicación de terceros, utilizando el WriteCommandReceiver, puede realizar las siguientes acciones: llamar a un número de teléfono, restablecer el dispositivo de fábrica, tomar imágenes de la pantalla, grabar la pantalla en un vídeo, instalar aplicaciones, inyectar eventos, obtener el registro de Android y otros. Además, el componente com.adups.fota.sysoper.TaskService hará una solicitud a una URL de http://rebootv5.adsunflower.com/ps/fetch.do donde los comandos en el array String con una clave de sf en el objeto JSON enviado de vuelta por el servidor se ejecutará como el usuario del sistema. Dado que la conexión se realiza a través de HTTP, es vulnerable a un ataque MITM."
}
],
"lastModified": "2026-06-17T00:39:07.903",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:adups:adups_fota:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D8B2E488-EEE4-4C16-B1F6-BD5847A0DE1A"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}