CVE-2011-4872: Htc Desire Hd
Low severity, CVSS 2.6. EPSS: 1.3% chance of exploitation in the next 30 days.
Multiple HTC Android devices including Desire HD FRG83D and GRI40, Glacier FRG83, Droid Incredible FRF91, Thunderbolt 4G FRG83D, Sensation Z710e GRI40, Sensation 4G GRI40, Desire S GRI40, EVO 3D GRI40, and EVO 4G GRI40 allow remote attackers to obtain 802.1X Wi-Fi credentials and SSID via a crafted application that uses the android.permission.ACCESS_WIFI_STATE permission to call the toString method on the WifiConfiguration class.
Affected products
- Htc Desire Hd: version frg83d only; version gri40 only
- Htc Desire S: version gri40 only
- Htc Droid Incredible: version frf91 only
- Htc Evo 3d: version gri40 only
- Htc Evo 4g: version gri40 only
- Htc Glacier: version frg83 only
- Htc Sensation 4g: version gri40 only
- Htc Sensation z710e: version gri40 only
- Htc Thunderbolt 4g: version frg83d only
Published 2012-02-05. Last modified 2026-06-16.