Bluebird devices contain a pre-loaded file manager...
Moderate severity
Unreviewed
Published
Jul 17, 2025
to the GitHub Advisory Database
Description
Published by the National Vulnerability Database
Jul 17, 2025
Published to the GitHub Advisory Database
Jul 17, 2025
Bluebird devices contain a pre-loaded file manager application. This application exposes an unsecured service provider "com.bluebird.system.koreanpost.IsdcardRemoteService". A local attacker can bind to the AIDL-type service to copy and delete arbitrary files from device's storage with system-level permissions.
Version 1.4.4 is vulnerable, vendor reverted vulnerable versions to older version: 1.3.6
References