CVE-2021-41849: Infoleak
An issue was discovered in Luna Simo PPR1.180610.011/202001031830. It sends the following Personally Identifiable Information (PII) in plaintext using HTTP to servers located in China: user's list of installed apps and device International Mobile Equipment Identity (IMEI). This PII is transmitted to log.skyroam.com.cn using HTTP, independent of whether the user uses the Simo software.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-41849?
The severity of CVE-2021-41849 is medium with a CVSS score of 5.5.
Which devices are affected by CVE-2021-41849?
Bluproducts G90 Firmware, Bluproducts G9 Firmware, Wikomobile Tommy 3 Firmware, and Luna Simo Firmware are affected by CVE-2021-41849.
What information is sent in plaintext by CVE-2021-41849?
CVE-2021-41849 sends Personally Identifiable Information (PII) including the user's list of installed apps and device IMEI in plaintext over HTTP.
Are Bluproducts G90 and Wikomobile Tommy 3 vulnerable to CVE-2021-41849?
No, Bluproducts G90 and Wikomobile Tommy 3 are not vulnerable to CVE-2021-41849.
Where can I find more information about CVE-2021-41849?
You can find more information about CVE-2021-41849 at the following references: [https://athack.com/session-details/401](https://athack.com/session-details/401), [https://simowireless.com/](https://simowireless.com/), [https://www.kryptowire.com/android-firmware-2022/](https://www.kryptowire.com/android-firmware-2022/).