CVE-2026-3669 Details
Description
A security vulnerability has been detected in Freedom Factory dGEN1 up to 20260221. This impacts the function AlarmService of the component com.dgen.alarm. Such manipulation leads to improper authorization. The attack needs to be performed locally. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
A broken authorization vulnerability has been identified in the Freedom Factory dGEN1 application, specifically in versions prior to 20260221. The issue resides within the AlarmService component of the com.dgen.alarm package. The vulnerability allows local applications to manipulate an exported BroadcastReceiver, StopReceiver, without proper authorization. This exploitation can lead to the unauthorized cancellation of active alarms, dismissal of alarm notifications, and removal of scheduled alarms, all without user interaction. Consequently, users may miss important alerts or reminders.
The StopReceiver should be marked as 'android:exported="false"' if external access is not needed. If it must remain exported, a custom permission should be enforced to control access, and the receiver should validate the identity of the caller. Alternatively, alarm-control actions could be restricted to internal application components only.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Mar 7, 2026CISA-ADP
Assessed Mar 11, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://gist.github.com/Lytes/2bd9cb3faf89b114754f00292beabb38 | [email protected] | Technical Analysis |
| https://vuldb.com/?ctiid.349557 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/?id.349557 | [email protected] | AdvisoryExploitPartial Content |
| https://vuldb.com/?submit.764703 | [email protected] | ExploitTechnical Description |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-266 | Incorrect Privilege Assignment | [email protected] |
| CWE-285 | Improper Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Freedom Factory dGEN1 | All versions |
CPE
Remediation
| |
| com.dgen.alarm | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 29, 2026 | Data Remediation | [email protected] |
| Mar 7, 2026 | New CVE Received | [email protected] |
Volerion