• Latest
  • Trending
Critical Vulnerabilities Found in Android Remote Keyboard Apps – Cyber ​​Security News

Critical Vulnerabilities Found in Android Remote Keyboard Apps – Cyber ​​Security News

08.12.2022
Ohio man pleads guilty to unlawfully robbing more than 712 people seized… – Department of Justice

Former Coinbase Insider Pleads Guilty in First-Ever Cryptocurrency… – Department of Justice

07.02.2023
Microsoft Teams just made me move my football team to… – Windows Central

Microsoft Teams just made me move my football team to… – Windows Central

07.02.2023

Super Bowl 2023 Time, Date: TV Channel, Live Stream Eagles vs. Chiefs in Super Bowl LVII

07.02.2023
Maya Jama is partying with friends in Dubai… but a bomb will hit the villa

Maya Jama is partying with friends in Dubai… but a bomb will hit the villa

07.02.2023
Maria Menounos and Keven Undergaro are "Beyond Excitement" expecting her first child

Maria Menounos and Keven Undergaro are "Beyond Excitement" expecting her first child

07.02.2023
Engineers and search dogs sent to Turkey and Syria after quake – The Associated Press – en Español

Engineers and search dogs sent to Turkey and Syria after quake – The Associated Press – en Español

07.02.2023
11 Best Body Massage Oils 2023 for Soothing At-Home Treatment – Allure

11 Best Body Massage Oils 2023 for Soothing At-Home Treatment – Allure

07.02.2023
Man Utd v Leeds: Score Rashford, Fernandes and Struijk to be cautioned at 33/1 with Betfred

Man Utd v Leeds: Score Rashford, Fernandes and Struijk to be cautioned at 33/1 with Betfred

07.02.2023
macOS 11.7.3 breaks Safari’s favorite icons – MacRumors

macOS 11.7.3 breaks Safari’s favorite icons – MacRumors

07.02.2023

Chiefs vs Eagles picks, spread, odds, start time: Super Bowl 57 predictions from an NFL expert on a 103-74 run

07.02.2023
Billie Eilish announces two ‘Happier Than Ever’ hometown encore shows at Kia Forum – Reuters

Billie Eilish announces two ‘Happier Than Ever’ hometown encore shows at Kia Forum – Reuters

07.02.2023
‘America’s Got Talent: All-Stars’ Episode 6 Performances Ranked: Worst to Best 10 Acts – Gold Derby

‘America’s Got Talent: All-Stars’ Episode 6 Performances Ranked: Worst to Best 10 Acts – Gold Derby

07.02.2023
Tuesday, February 7, 2023
  • World
  • Economics
  • Sport
    • Basketball
    • Football
    • Nfl
    • Golf
    • F1
    • UFC
  • Technology
  • Culture
    • Arts
  • Media
    • Film
    • Celebs
    • TV
  • LifeStyle
    • Auto
  • Travel
OLTNEWS
  • World
  • Economics
  • Sport
    • Basketball
    • Football
    • Nfl
    • Golf
    • F1
    • UFC
  • Technology
  • Culture
    • Arts
  • Media
    • Film
    • Celebs
    • TV
  • LifeStyle
    • Auto
  • Travel
OLTNEWS
No Result
View All Result

Home » Technology » Critical Vulnerabilities Found in Android Remote Keyboard Apps – Cyber ​​Security News

Critical Vulnerabilities Found in Android Remote Keyboard Apps – Cyber ​​Security News

08/12/2022 19:28:22
in Technology
0
0
SHARES
Share on WhatsappShare on Facebook

Related posts

Microsoft Teams just made me move my football team to… – Windows Central

Microsoft Teams just made me move my football team to… – Windows Central

07.02.2023
macOS 11.7.3 breaks Safari’s favorite icons – MacRumors

macOS 11.7.3 breaks Safari’s favorite icons – MacRumors

07.02.2023

Researchers have discovered critical remote code execution vulnerabilities in numerous remote keyboard apps for Android. Given their number of downloads, the vulnerable apps have put the security of more than 2 million Android users at risk.

Android Remote Keyboard App Vulnerabilities

According to a recent advisory from Synopsys Cybersecurity Research Center (CyRC), they have noticed numerous security vulnerabilities in several Android remote keyboard apps. In fact, the vulnerable apps even included a remote mouse app.

Specifically, these apps include Lazy Mouse, Telepad, and PC Keyboard, which allow an Android device to act as a remote keyboard or mouse for computers. As for the vulnerabilities, CyRC has spotted the following critical issues with the apps.

  • CVE-2022-45477 (CVSS 9.8): This vulnerability in the Telepad application allowed unauthenticated remote users to execute codes on the target server.
  • CVE-2022-45479 (CVSS 9.8): A critical vulnerability affecting the PC keyboard application allowing unauthenticated remote users to execute commands on the target server.
  • CVE-2022-45481 (CVSS 9.8): A code execution vulnerability in the Lazy Mouse application that allowed access to unauthenticated remote users. This flaw existed due to the lack of a password requirement in the default configuration.
  • CVE-2022-45482 (CVSS 9.8): The lack of rate limiting and the requirement for a weak password in the Lazy Mouse app allowed unauthenticated remote attackers to brute force a PIN and execute arbitrary commands.

Additionally, the researchers also noticed how the three apps exposed data in transit to a potential MiTM attacker positioned between the server and the device. They observed Telepad (CVE-2022-45478; CVSS 5.1), PC keyboard (CVE-2022-45480; CVSS 5.1) and lazy mouse (CVE-2022-45483; CVSS 5.1) transmitting sensitive data, including key presses, in clear text.

No patches available for all three apps

The vulnerabilities typically existed in Telepad versions 1.0.7 and earlier, PC Keyboard versions 30 and earlier, and Lazy Mouse versions 2.0.1 and earlier. The researchers explained that despite multiple attempts to contact the developers, they got no response.

Additionally, the apps do not appear to be under maintenance, which means the vulnerabilities put users of active apps at risk. Therefore, they urge all users to remove such apps from their devices to avoid potential risks.

Let us know your thoughts in the comments.

Related

Previous Post

Rihanna, Taylor Swift and Beyoncé make Forbes’ Most Powerful Women list – Yahoo Entertainment

Next Post

Former US spy Anne Sacoolas avoids prison for the death of teenage motorcyclist Harry Dunn

Related Posts

Microsoft Teams just made me move my football team to… – Windows Central
Technology

Microsoft Teams just made me move my football team to… – Windows Central

07.02.2023
0

Microsoft recently announced that it will be retiring the current free version of Teams on April 12, 2023. A new...

Read more
macOS 11.7.3 breaks Safari’s favorite icons – MacRumors

macOS 11.7.3 breaks Safari’s favorite icons – MacRumors

07.02.2023
Dragon Ball Super Previews Power Absorbed: Android 18 Z-Awaken

Dragon Ball Super Previews Power Absorbed: Android 18 Z-Awaken

07.02.2023

Samsung would have prepared a fix for an embarrassing SSD problem

07.02.2023

Huawei P60 passes on Geekbench with Android 13 and Snapdragon 778 – HC Newsroom

07.02.2023

Why can the success of the Call of Duty series heat up the Microsoft-Sony “war”?

07.02.2023
Load More
Next Post
Former US spy Anne Sacoolas avoids prison for the death of teenage motorcyclist Harry Dunn

Former US spy Anne Sacoolas avoids prison for the death of teenage motorcyclist Harry Dunn

Recent Posts

  • Former Coinbase Insider Pleads Guilty in First-Ever Cryptocurrency… – Department of Justice
  • Microsoft Teams just made me move my football team to… – Windows Central
  • Super Bowl 2023 Time, Date: TV Channel, Live Stream Eagles vs. Chiefs in Super Bowl LVII
  • Maya Jama is partying with friends in Dubai… but a bomb will hit the villa
  • Maria Menounos and Keven Undergaro are "Beyond Excitement" expecting her first child

Archives

  • February 2023
  • January 2023
  • December 2022
  • November 2022
  • October 2022
  • September 2022
  • August 2022
  • July 2022
  • June 2022
  • May 2022
  • April 2022
  • March 2022
  • February 2022
  • January 2022
  • December 2021
  • November 2021
  • October 2021
  • September 2021
  • August 2021
  • July 2021
  • June 2021
  • May 2021
  • April 2021
  • March 2021
  • February 2021
  • January 2021
  • December 2020
  • November 2020
  • October 2020
  • September 2020
  • August 2020
  • July 2020
  • June 2020
  • May 2020
  • April 2020
  • March 2020
  • 0
  • EN

© 2020

No Result
View All Result
  • World
  • Economics
  • Sport
    • Basketball
    • Football
    • Nfl
    • Golf
    • F1
    • UFC
  • Technology
  • Culture
    • Arts
  • Media
    • Film
    • Celebs
    • TV
  • LifeStyle
    • Auto
  • Travel

© 2020

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.