Version 1.4.4 is vulnerable, vendor reverted vulnerable versions to older version: 1.3.6
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-21764 | Bluebird devices contain a pre-loaded file manager application. This application exposes an unsecured service provider "com.bluebird.system.koreanpost.IsdcardRemoteService". A local attacker can bind to the AIDL-type service to copy and delete arbitrary files from device's storage with system-level permissions. Version 1.4.4 is vulnerable, vendor reverted vulnerable versions to older version: 1.3.6 |
| Link | Providers |
|---|---|
| https://cert.pl/en/posts/2025/07/CVE-2025-5344 |
|
Thu, 17 Jul 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 17 Jul 2025 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Bluebird devices contain a pre-loaded file manager application. This application exposes an unsecured service provider "com.bluebird.system.koreanpost.IsdcardRemoteService". A local attacker can bind to the AIDL-type service to copy and delete arbitrary files from device's storage with system-level permissions. Version 1.4.4 is vulnerable, vendor reverted vulnerable versions to older version: 1.3.6 | |
| Title | Exposed AIDL service allowing to read and delete files with system-level privileges in Bluebird filemanager application | |
| Weaknesses | CWE-926 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: CERT-PL
Published:
Updated: 2025-07-17T13:51:53.408Z
Reserved: 2025-05-30T06:40:15.514Z
Link: CVE-2025-5345
Updated: 2025-07-17T13:51:48.922Z
Status : Deferred
Published: 2025-07-17T13:15:23.217
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-5345
No data.
OpenCVE Enrichment
No data.
EUVD