CVE-2026-0634
7.8TECNO Mobile · TECNO Pova7 Pro 5G
A command injection vulnerability in the AssistFeedbackService of the TECNO Pova7 Pro 5G allows local applications to execute arbitrary code with system-level privileges.
Executive summary
A high-severity command injection vulnerability in the TECNO Pova7 Pro 5G allows local malicious applications to escalate privileges to the system level.
Vulnerability
This is a command injection vulnerability (CWE-88) occurring within the AssistFeedbackService. The vulnerability requires the attacker to be an authenticated local user (a malicious app installed on the device) to trigger the injection and achieve system-level code execution.
Business impact
The ability for a local application to execute code as the system user represents a total compromise of the affected mobile device. Given the CVSS score of 7.8, this vulnerability poses a significant risk to data confidentiality, integrity, and availability, as the attacker could bypass device sandboxing, access sensitive user data, or install persistent malware.
Remediation
Immediate Action: Users should check for and apply the latest security updates provided by TECNO Mobile via the device settings menu. If an update is not yet available, avoid installing applications from untrusted sources to minimize the risk of local exploitation.
Proactive Monitoring: Security administrators managing enterprise fleets should monitor for anomalous system-level process execution or unexpected modifications to system files on affected devices.
Compensating Controls: Ensure that mobile device management (MDM) policies restrict the installation of apps to only authorized or vetted application stores to prevent the introduction of malicious local packages.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
This vulnerability presents a severe risk by allowing privilege escalation to the system level on the affected hardware. We strongly recommend that all organizations using the TECNO Pova7 Pro 5G prioritize the deployment of vendor-supplied security patches as soon as they are released to prevent potential unauthorized system access.