Insecure File Transfer in SHAREit by Lenovo for Android Devices
CVE-2016-1492

6.1MEDIUM

Key Information:

Vendor
Lenovo
Status
Vendor
CVE Published:
26 January 2016

Summary

Lenovo SHAREit for Android prior to version 3.5.48_ww has a significant security vulnerability allowing unauthorized access through its WiFi hotspot feature. When configured to receive files, the hotspot lacks a password requirement, enabling attackers within the WLAN coverage area to execute remote file transfer exploitation. This breaches the confidentiality of data exchanged, posing risks of unauthorized data access.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.