cvedb.io
CVE-2018-14988
HIGH · CVSS 7.5
EPSS exploitation probability: 0%
Published 2018-12-28T21:29:00.557 · Last modified 2026-06-17T01:42:01.750

Summary

The MXQ TV Box 4.4.2 Android device with a build fingerprint of MBX/m201_N/m201_N:4.4.2/KOT49H/20160106:user/test-keys contains the Android framework with a package name of android (versionCode=19, versionName=4.4.2-20170213) that contains an exported broadcast receiver application component that, when called, will make the device inoperable. The vulnerable component named com.android.server.SystemRestoreReceiver will write a value of --restore_system\n--locale=<localeto the /cache/recovery/command file and boot into recovery mode. During this process, it appears that when booting into recovery mode, the system partition gets formatted or modified and will be unable to boot properly thereafter. After the device wouldn't boot properly, a factory reset of the device in recovery mode does not

Affected products

mxq_project — mxq_tv_box_firmware

Does this affect you?

Add your gear to cvedb and we'll alert you only when mxq_project ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.