|
ZTE Corp, the world's No.4 handset vendor and one of two Chinese companies under U.S. scrutiny over security concerns, said one of its mobile phone models sold in the United States contains a vulnerability that researchers say could allow others to control the device. The hole affects ZTE's Score model that runs on Google Inc's Android operating system and was described by one researcher as "highly unusual."
"I've never seen it before," said Dmitri Alperovitch, co-founder of cybersecurity firm, CrowdStrike. The hole, usually called a backdoor, allows anyone with the hardwired password to access the affected phone, he added.
ZTE and fellow Chinese telecommunications equipment manufacturer, Huawei Technologies Co Ltd, have been stymied in their attempts to expand in the United States over concerns they are linked to the Chinese government, though both companies have denied this. Most such concerns have centered on the fear of backdoors or other security vulnerabilities in telecommunications infrastructure equipment rather than in consumer devices.
Last month a U.S. congressional panel singled out Huawei and ZTE by approving a measure designed to search and clear the U.S. nuclear-weapons complex of any technology produced by the two companies. ![]() One of the largest telecom hardware manufacturers out there
Reports of the ZTE vulnerability first surfaced this week in an anonymous posting on the code-sharing website, pastebin.com. Others have since alleged that other ZTE models, including the Skate, also contain the vulnerability. The password is readily available online.
ZTE said it had confirmed the vulnerability on the Score phone, but denied it affected other models.
"ZTE is actively working on a security patch and expects to send the update over-the-air to affected users in the very near future," ZTE said in an emailed statement. "We strongly urge affected users to download and install the patch as soon as it is rolled out to their devices."
Alperovitch said his team had researched the vulnerability and found that the backdoor was deliberate because it was being used as a way for ZTE to update the phone's software. It is a question, he said, of whether the purpose was malicious or just sloppy programming.
"It could very well be that they're not very good developers or they could be doing this for nefarious purposes," he said.
While security researchers have highlighted security holes in Android and other mobile operating systems, it is rare to find a vulnerability apparently inserted by the hardware manufacturer.
"I have never seen this before. There are rumors about backdoors in Chinese equipment floating around," Alperovitch said. "That's why it's so shocking to see it blatantly on a device."
A Google spokesman declined to comment. |
Tags: ZTE Corp , ZTE Mobile Phones , ZTE Mobile Vulnerability , ZTE Security issues , CrowdStrike , Mobile Control
SPOTLIGHT
Microsoft unveils next-gen console, dubbed...
22 May, 2013, 09:02 AM
Google+ mobile site updated to look more in
22 May, 2013, 09:51 AM
How To: Root the Samsung Galaxy S4 I9500
20 May, 2013, 02:25 PM
Samsung Galaxy S4 vs HTC One vs Nokia Lumia 920: Camera shootout
13 May, 2013, 05:40 PM IST
4.7-inch Galaxy Grand Quattro launched for Rs 17,290
20 May, 2013, 04:20 PM IST
6 Things to look for when buying a 'future-proof' smartphone
18 May, 2013, 01:07 PM IST
Nexus 4 finally launched in India for Rs 25,999
16 May, 2013, 12:40 PM IST
First Impressions: Sony Xperia SP
13 May, 2013, 10:42 AM IST
Global smartphone shipments to exceed that of feature phones in 2013: Report
21 May, 2013, 05:55 PM
HTC One Google Edition coming soon, tweets serial leaker
21 May, 2013, 02:35 PM
Jolla out to prove a point with first Sailfish smartphone
21 May, 2013, 01:58 PM
6 Things to look for when buying a 'future-proof' smartphone
If you’re out looking for a new smartphone, then there are a couple of...
Smartphone launches this week: May 13-17
In the hustle-bustle of everyday life, you might have missed the launch of
Panasonic P51: A Specifications Review
Priced at Rs 26,990, the P51 will face some really tough competition from...
21 May, 2013, 01:00 PM IST
7.0
We’ve already established that the Lumia 720 is Nokia’s best effort as far as Windows Phone 8 handsets go. This could soon change once the Lumia 925 hits markets, but as it stands now, the Lumia 720 offers the best blend of features and performance, wrapped in a beautiful package that’s quite affordable.
Microsoft unveils next-gen console, dubbed the Xbox One
Sai Krishna Vajjala
Wed May 22, 10:56:09
Mid-range Swipe 9X launched for Rs 8,999
Madhuri Ramani
Wed May 22, 10:36:03
92 percent of Google Translate users are from outside US
Manjeet Singh
Wed May 22, 10:32:08
Global smartphone shipments to exceed that
HTC One Google Edition coming soon, tweets
Apple iPad 5 trial production to begin...
10.1-inch Sony Xperia Tablet Z launches at
New Call of Duty: Ghosts trailer shows...
Microsoft unveils next-gen console, dubbed


















reddit

Mixx
Facebook
Twitter
Digg
delicious
MySpace














