• Latest
  • Trending
Critical Vulnerabilities Found in Android Remote Keyboard Apps – Cyber ​​Security News

Critical Vulnerabilities Found in Android Remote Keyboard Apps – Cyber ​​Security News

08.12.2022

California is set to pass an Amsterdam-style law that will allow cannabis cafes to open across the state.

27.09.2023
US Lawmakers Push SEC to Immediately Approve Bitcoin ETF – CoinGape

US Lawmakers Push SEC to Immediately Approve Bitcoin ETF – CoinGape

27.09.2023
WhatsApp plans to change UI design for Android users with new icons and colors, details here

WhatsApp plans to change UI design for Android users with new icons and colors, details here

27.09.2023
Solange Knowles makes a very discreet arrival in a black hat and mask as she leaves Sydney Airport ahead of the show

Solange Knowles makes a very discreet arrival in a black hat and mask as she leaves Sydney Airport ahead of the show

27.09.2023
16 Dramatic Romances on Netflix to Watch Once the Next Series is Over

16 Dramatic Romances on Netflix to Watch Once the Next Series is Over

27.09.2023
Oil falls as U.S. rate hike expectations offset tight supply outlook – Reuters.com

Oil prices rise as markets focus on tighter supply – Reuters

27.09.2023
Nikon Announces NIKKOR Z 135mm F1.8 S Plena Lens;  Hands-on YouTube video review at B&H Photo

Nikon Announces NIKKOR Z 135mm F1.8 S Plena Lens; Hands-on YouTube video review at B&H Photo

27.09.2023
Does Katy Perry sell her music?  ¡All the context you need to know!  – The event

Does Katy Perry sell her music? ¡All the context you need to know! – The event

27.09.2023
FBI investigating whether Egyptian intelligence played role in Menendez case – NBC News

FBI investigating whether Egyptian intelligence played role in Menendez case – NBC News

27.09.2023
Crypto Price Today: Bitcoin Holds $26,000;  Ethereum nears $1,600;  The polygon falls by 3% – Business Today

Crypto Price Today: Bitcoin Holds $26,000; Ethereum nears $1,600; The polygon falls by 3% – Business Today

27.09.2023
China lists mobile app stores that comply with new rule, but Apple… – Reuters

China lists mobile app stores that comply with new rule, but Apple… – Reuters

27.09.2023
Carolyn Hax: Is it “selfish” to ask your dying husband to hold on a little longer?

Carolyn Hax: Is it “selfish” to ask your dying husband to hold on a little longer?

27.09.2023
Wednesday, September 27, 2023
  • World
  • Economics
  • Sport
    • Basketball
    • Football
    • Nfl
    • Golf
    • F1
    • UFC
  • Technology
  • Culture
    • Arts
  • Media
    • Film
    • Celebs
    • TV
  • LifeStyle
    • Auto
  • Travel
OLTNEWS
  • World
  • Economics
  • Sport
    • Basketball
    • Football
    • Nfl
    • Golf
    • F1
    • UFC
  • Technology
  • Culture
    • Arts
  • Media
    • Film
    • Celebs
    • TV
  • LifeStyle
    • Auto
  • Travel
OLTNEWS
No Result
View All Result

Home » Technology » Critical Vulnerabilities Found in Android Remote Keyboard Apps – Cyber ​​Security News

Critical Vulnerabilities Found in Android Remote Keyboard Apps – Cyber ​​Security News

08/12/2022 19:28:22
in Technology
0
0
SHARES
Share on WhatsappShare on Facebook

Researchers have discovered critical remote code execution vulnerabilities in numerous remote keyboard apps for Android. Given their number of downloads, the vulnerable apps have put the security of more than 2 million Android users at risk.

Android Remote Keyboard App Vulnerabilities

According to a recent advisory from Synopsys Cybersecurity Research Center (CyRC), they have noticed numerous security vulnerabilities in several Android remote keyboard apps. In fact, the vulnerable apps even included a remote mouse app.

Specifically, these apps include Lazy Mouse, Telepad, and PC Keyboard, which allow an Android device to act as a remote keyboard or mouse for computers. As for the vulnerabilities, CyRC has spotted the following critical issues with the apps.

  • CVE-2022-45477 (CVSS 9.8): This vulnerability in the Telepad application allowed unauthenticated remote users to execute codes on the target server.
  • CVE-2022-45479 (CVSS 9.8): A critical vulnerability affecting the PC keyboard application allowing unauthenticated remote users to execute commands on the target server.
  • CVE-2022-45481 (CVSS 9.8): A code execution vulnerability in the Lazy Mouse application that allowed access to unauthenticated remote users. This flaw existed due to the lack of a password requirement in the default configuration.
  • CVE-2022-45482 (CVSS 9.8): The lack of rate limiting and the requirement for a weak password in the Lazy Mouse app allowed unauthenticated remote attackers to brute force a PIN and execute arbitrary commands.

Additionally, the researchers also noticed how the three apps exposed data in transit to a potential MiTM attacker positioned between the server and the device. They observed Telepad (CVE-2022-45478; CVSS 5.1), PC keyboard (CVE-2022-45480; CVSS 5.1) and lazy mouse (CVE-2022-45483; CVSS 5.1) transmitting sensitive data, including key presses, in clear text.

No patches available for all three apps

The vulnerabilities typically existed in Telepad versions 1.0.7 and earlier, PC Keyboard versions 30 and earlier, and Lazy Mouse versions 2.0.1 and earlier. The researchers explained that despite multiple attempts to contact the developers, they got no response.

Additionally, the apps do not appear to be under maintenance, which means the vulnerabilities put users of active apps at risk. Therefore, they urge all users to remove such apps from their devices to avoid potential risks.

Let us know your thoughts in the comments.

Related posts

WhatsApp plans to change UI design for Android users with new icons and colors, details here

WhatsApp plans to change UI design for Android users with new icons and colors, details here

27.09.2023
Nikon Announces NIKKOR Z 135mm F1.8 S Plena Lens;  Hands-on YouTube video review at B&H Photo

Nikon Announces NIKKOR Z 135mm F1.8 S Plena Lens; Hands-on YouTube video review at B&H Photo

27.09.2023

Researchers have discovered critical remote code execution vulnerabilities in numerous remote keyboard apps for Android. Given their number of downloads, the vulnerable apps have put the security of more than 2 million Android users at risk.

Android Remote Keyboard App Vulnerabilities

According to a recent advisory from Synopsys Cybersecurity Research Center (CyRC), they have noticed numerous security vulnerabilities in several Android remote keyboard apps. In fact, the vulnerable apps even included a remote mouse app.

Specifically, these apps include Lazy Mouse, Telepad, and PC Keyboard, which allow an Android device to act as a remote keyboard or mouse for computers. As for the vulnerabilities, CyRC has spotted the following critical issues with the apps.

  • CVE-2022-45477 (CVSS 9.8): This vulnerability in the Telepad application allowed unauthenticated remote users to execute codes on the target server.
  • CVE-2022-45479 (CVSS 9.8): A critical vulnerability affecting the PC keyboard application allowing unauthenticated remote users to execute commands on the target server.
  • CVE-2022-45481 (CVSS 9.8): A code execution vulnerability in the Lazy Mouse application that allowed access to unauthenticated remote users. This flaw existed due to the lack of a password requirement in the default configuration.
  • CVE-2022-45482 (CVSS 9.8): The lack of rate limiting and the requirement for a weak password in the Lazy Mouse app allowed unauthenticated remote attackers to brute force a PIN and execute arbitrary commands.

Additionally, the researchers also noticed how the three apps exposed data in transit to a potential MiTM attacker positioned between the server and the device. They observed Telepad (CVE-2022-45478; CVSS 5.1), PC keyboard (CVE-2022-45480; CVSS 5.1) and lazy mouse (CVE-2022-45483; CVSS 5.1) transmitting sensitive data, including key presses, in clear text.

No patches available for all three apps

The vulnerabilities typically existed in Telepad versions 1.0.7 and earlier, PC Keyboard versions 30 and earlier, and Lazy Mouse versions 2.0.1 and earlier. The researchers explained that despite multiple attempts to contact the developers, they got no response.

Additionally, the apps do not appear to be under maintenance, which means the vulnerabilities put users of active apps at risk. Therefore, they urge all users to remove such apps from their devices to avoid potential risks.

Let us know your thoughts in the comments.

Previous Post

Rihanna, Taylor Swift and Beyoncé make Forbes’ Most Powerful Women list – Yahoo Entertainment

Next Post

Former US spy Anne Sacoolas avoids prison for the death of teenage motorcyclist Harry Dunn

Related Posts

WhatsApp plans to change UI design for Android users with new icons and colors, details here
Technology

WhatsApp plans to change UI design for Android users with new icons and colors, details here

27.09.2023
0

New Delhi,UPDATED: September 27, 2023, 10:46 AM ISTMeta plans to give its popular messaging app WhatsApp a facelift. The company...

Read more
Nikon Announces NIKKOR Z 135mm F1.8 S Plena Lens;  Hands-on YouTube video review at B&H Photo

Nikon Announces NIKKOR Z 135mm F1.8 S Plena Lens; Hands-on YouTube video review at B&H Photo

27.09.2023
China lists mobile app stores that comply with new rule, but Apple… – Reuters

China lists mobile app stores that comply with new rule, but Apple… – Reuters

27.09.2023

Despite sales up 10%, Samsung reportedly reduced its production targets for the Fold 5 and Flip 5 – PhoneArena

27.09.2023

FDx Advisors Inc. Increases Its Stake in Sony Group Co. by 93.4… – Best Stocks

27.09.2023

Safari 17 with enhanced private browsing now available for macOS Ventura and macOS Monterey – AppleInsider

27.09.2023
Load More
Next Post
Former US spy Anne Sacoolas avoids prison for the death of teenage motorcyclist Harry Dunn

Former US spy Anne Sacoolas avoids prison for the death of teenage motorcyclist Harry Dunn

Recent Posts

  • California is set to pass an Amsterdam-style law that will allow cannabis cafes to open across the state.
  • US Lawmakers Push SEC to Immediately Approve Bitcoin ETF – CoinGape
  • WhatsApp plans to change UI design for Android users with new icons and colors, details here
  • Solange Knowles makes a very discreet arrival in a black hat and mask as she leaves Sydney Airport ahead of the show
  • 16 Dramatic Romances on Netflix to Watch Once the Next Series is Over

Archives

  • September 2023
  • August 2023
  • July 2023
  • April 2023
  • March 2023
  • February 2023
  • January 2023
  • December 2022
  • November 2022
  • October 2022
  • September 2022
  • August 2022
  • July 2022
  • June 2022
  • May 2022
  • April 2022
  • March 2022
  • February 2022
  • January 2022
  • December 2021
  • November 2021
  • October 2021
  • September 2021
  • August 2021
  • July 2021
  • June 2021
  • May 2021
  • April 2021
  • March 2021
  • February 2021
  • January 2021
  • December 2020
  • November 2020
  • October 2020
  • September 2020
  • August 2020
  • July 2020
  • June 2020
  • May 2020
  • April 2020
  • March 2020
  • EN

© 2020

No Result
View All Result
  • World
  • Economics
  • Sport
    • Basketball
    • Football
    • Nfl
    • Golf
    • F1
    • UFC
  • Technology
  • Culture
    • Arts
  • Media
    • Film
    • Celebs
    • TV
  • LifeStyle
    • Auto
  • Travel

© 2020

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.