AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2018-14066

CRITICAL · CVSS 9.8 EPSS 0.43%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2018-07-15 · Last synced 2026-08-04

CyberRota Analysis

This is a critical severity vulnerability with a CVSS score of 9.8. It affects Android. It involves a SQL injection risk.

CVE
CVE-2018-14066
Severity
CRITICAL
CVSS
9.8
EPSS
0.43%
Android

Original NVD Description

The content://wappush content provider in com.android.provider.telephony, as found in some custom ROMs for Android phones, allows SQL injection. One consequence is that an application without the READ_SMS permission can read SMS messages. This affects Infinix X571 phones, as well as various Lenovo phones (such as the A7020) that have since been fixed by Lenovo.

Related CVEs

Other vulnerabilities affecting the same vendor(s)