{"id":"CVE-2026-49004","published":"2026-08-05T07:16:37.333","lastModified":"2026-08-05T15:16:52.163","description":"The built-in PostgreSQL service on the mobile device suffers from misconfiguration flaws and command injection vulnerabilities. This service listens on a specific port, runs with root privileges, and is protected by weak credentials. The database supports the COPY FROM PROGRAM syntax, allowing local attackers to bypass Android's permission sandbox and gain full root access.","cvssScore":6.5,"cvssSeverity":"MEDIUM","cvssVector":"CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L","cwes":["CWE-89"],"vendors":[],"products":[],"references":[{"url":"https://support.zte.com.cn/zte-iccp-isupport-webui/bulletin/detail/460174866982027405","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"The flaw allows local attackers to exploit misconfigured PostgreSQL service command injection vulnerabilities to gain full root access on affected devices.","exploitability":"Exploitation requires root privileges and knowledge of weak credentials but is relatively straightforward given the service's misconfiguration.","blast_radius":"If exploited, the impact could be severe, leading to complete control over the device and potential data exfiltration or system compromise.","remediation":"Update and secure the PostgreSQL service by changing default credentials and limiting its privileges to non-root levels.","tags":["rce","auth-bypass","local-privilege-escalation"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-08-11T07:06:46.957Z"}}