CVE-2025-31710

In engineermode service, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed.
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:o:google:android:13.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:14.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:15.0:*:*:*:*:*:*:*
OR cpe:2.3:h:unisoc:s8000:-:*:*:*:*:*:*:*
cpe:2.3:h:unisoc:sc9863a:-:*:*:*:*:*:*:*
cpe:2.3:h:unisoc:t606:-:*:*:*:*:*:*:*
cpe:2.3:h:unisoc:t612:-:*:*:*:*:*:*:*
cpe:2.3:h:unisoc:t616:-:*:*:*:*:*:*:*
cpe:2.3:h:unisoc:t750:-:*:*:*:*:*:*:*
cpe:2.3:h:unisoc:t760:-:*:*:*:*:*:*:*
cpe:2.3:h:unisoc:t765:-:*:*:*:*:*:*:*
cpe:2.3:h:unisoc:t770:-:*:*:*:*:*:*:*
cpe:2.3:h:unisoc:t820:-:*:*:*:*:*:*:*
cpe:2.3:h:unisoc:t8300:-:*:*:*:*:*:*:*
cpe:2.3:h:unisoc:t9300:-:*:*:*:*:*:*:*

History

10 Jun 2025, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-03 06:15

Updated : 2025-06-10 15:15


NVD link : CVE-2025-31710

Mitre link : CVE-2025-31710

CVE.ORG link : CVE-2025-31710


JSON object : View

Products Affected

google

  • android

unisoc

  • t606
  • sc9863a
  • t765
  • t820
  • t612
  • t8300
  • t750
  • t616
  • t9300
  • t770
  • t760
  • s8000
CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')