The component com.transsion.tranfacmode.entrance.main.MainActivity in com.transsion.tranfacmode has no permission control and can be accessed by third-party apps which can construct intents to directly open adb debugging functionality without user interaction.
History

Wed, 17 Dec 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 17 Dec 2025 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google android
Tecno
Tecno factory Mode App
Vendors & Products Google
Google android
Tecno
Tecno factory Mode App

Wed, 17 Dec 2025 10:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269

Wed, 17 Dec 2025 10:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-862

Wed, 17 Dec 2025 07:15:00 +0000

Type Values Removed Values Added
References
Metrics cvssV4_0

{'score': 10, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


Wed, 17 Dec 2025 06:45:00 +0000

Type Values Removed Values Added
Description The component com.transsion.tranfacmode.entrance.main.MainActivity in com.transsion.tranfacmode has no permission control and can be accessed by third-party apps which can construct intents to directly open adb debugging functionality without user interaction.
Title Factory Mode App Exists Privilege Escalation Issue Allowing Third-Party Apps to Open ADB
Weaknesses CWE-269
References
Metrics cvssV4_0

{'score': 10, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: TECNOMobile

Published: 2025-12-17T06:20:59.672Z

Updated: 2025-12-17T18:47:26.941Z

Reserved: 2025-12-17T05:46:30.356Z

Link: CVE-2025-14817

cve-icon Vulnrichment

Updated: 2025-12-17T18:47:09.023Z

cve-icon NVD

Status : Received

Published: 2025-12-17T07:15:58.817

Modified: 2025-12-17T19:16:02.790

Link: CVE-2025-14817

cve-icon Redhat

No data.