CVE-2017-17763

Severity CVSS v4.0:
Pending analysis
Type:
CWE-311 Missing Encryption of Sensitive Data
Publication date:
19/12/2017
Last modified:
20/04/2025

Description

SuperBeam through 4.1.3, when using the LAN or WiFi Direct Share feature, does not use HTTPS or any integrity-protection mechanism for file transfer, which makes it easier for remote attackers to send crafted files, as demonstrated by APK injection.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:liveqos:superbeam:*:*:*:*:*:*:*:* 4.1.3 (including)


References to Advisories, Solutions, and Tools