CVE-2025-5345 Details
Description
Bluebird devices contain a pre-loaded file manager application. This application exposes an unsecured service provider "com.bluebird.system.koreanpost.IsdcardRemoteService". A local attacker can bind to the AIDL-type service to copy and delete arbitrary files from device's storage with system-level permissions. Version 1.4.4 is vulnerable, vendor reverted vulnerable versions to older version: 1.3.6
A vulnerability exists in the pre-loaded file manager application on Bluebird devices, specifically in version 1.4.4. The application exposes an unsecured AIDL-type service provider, 'com.bluebird.system.koreanpost.IsdcardRemoteService', which allows local attackers to bind to the service and gain system-level permissions to copy and delete arbitrary files from the device's storage.
Users can downgrade to version 1.3.6, which is not vulnerable, as the vendor has reverted vulnerable versions to this earlier release.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 17, 2025CISA-ADP
Assessed Jul 17, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://cert.pl/en/posts/2025/07/CVE-2025-5344 | [email protected] | AdvisoryBundleRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-926 | Improper Export of Android Application Components | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Bluebird com.bluebird.filemanagers | 1.4.4 (semver) |
CPE
Remediation
| |
| Bluebird com.bluebird.kiosk.launcher | All versions |
CPE
Remediation
| |
| Bluebird kr.co.bluebird.android.bbsettings | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jul 17, 2025 | New CVE Received | [email protected] |
Volerion