PT-2026-23882 · Freedom Factory+1 · Dgen1+1

·

CVE-2026-3671

·

Publicado

2026-03-07

·

Atualizado

2026-03-08

CVSS v3.1

3.3

Baixa

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Freedom Factory dGEN1 versions up to 20260221
Description A flaw exists in the TokenBalanceContentProvider function within the org.ethereumphone.walletmanager.testing123 component. A manipulation of this function can lead to improper authorization. Local access is required for exploitation. The exploit has been published. The vendor was contacted regarding this disclosure but did not respond.
Recommendations Versions prior to 20260221 should be updated. As a temporary workaround, consider restricting access to the TokenBalanceContentProvider function until a patch is available.

Exploit

Correção

Improper Authorization

Incorrect Privilege Assignment

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-3671

Produtos afetados

Dgen1
Org.Ethereumphone.Walletmanager.Testing123