CVE-2012-2949: ZTE Score M

High severity, CVSS 10.0. EPSS: 3.6% chance of exploitation in the next 30 days.

The ZTE sync_agent program for Android 2.3.4 on the Score M device uses a hardcoded ztex1609523 password to control access to commands, which allows remote attackers to gain privileges via a crafted application.

Affected products

Published 2012-05-29. Last modified 2026-06-16.