CVE-2024-13915

Android based smartphones from vendors such as Ulefone andKrger&Matz contain "com.pri.factorytest" application preloaded onto devices during manufacturing process.
The application"com.pri.factorytest"(version name: 1.0, version code: 1)exposes a com.pri.factorytest.emmc.FactoryResetService service allowing any application to perform a factory reset of the device.
Application update did not increment the APK version. Instead, it was bundled in OS builds released later than December 2024 (Ulefone) and April 2025 (Krger&Matz).
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
UNKNOWN
---
CERT-PLCNA
---
---
CISA-ADPADP
---
---