LiveActive security incident?Get immediate response
CVE Record

CVE-2018-15003: The Coolpad Defiant (Coolpad/cp3632a/cp3632a:7.1.1/NMF26F/099480857:user/release-keys) and the T-Mobile Rev...

The Coolpad Defiant (Coolpad/cp3632a/cp3632a:7.1.1/NMF26F/099480857:user/release-keys) and the T-Mobile Revvl Plus (Coolpad/alchemy/alchemy:7.1.1/143.14.171129.3701A-TMO/buildf_nj_02-206:user/release-keys) Android devices contain a pre-installed platform app with a package name of com.qualcomm.qti.telephony.extcarrierpack (versionCode=25, versionName=7.1.1) containing an exported broadcast receiver app component named com.qualcomm.qti.telephony.extcarrierpack.UiccReceiver that allows any app co-located on the device to programmatically perform a factory reset. In addition, the app initiating the factory reset does not require any permissions. A factory reset will remove all user data and apps from the device. This will result in the loss of any data that have not been backed up or synced externally. The capability to perform a factory reset is not directly available to third-party apps (those that the user installs themselves with the exception of enabled Mobile Device Management (MDM) apps), although this capability can be obtained by leveraging an unprotected app component of a pre-installed platform app.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysismoderate

Security readout for executives and security teams

Plain-English summary

This flaw lets any app already installed on certain Coolpad-manufactured Android phones trigger a factory reset without special permissions. The main business risk is data loss and device disruption, not remote system takeover. Evidence in the source bundle names specific older devices and does not show active exploitation.

Executive priority

Treat this as a managed-fleet hygiene issue with real data-loss impact. Prioritize if affected devices hold business data, lack reliable backups, or allow unmanaged app installation. It is less urgent than remotely exploitable mobile vulnerabilities based on the provided evidence.

Technical view

CVE-2018-15003 concerns an exported broadcast receiver, com.qualcomm.qti.telephony.extcarrierpack.UiccReceiver, in the preinstalled platform app com.qualcomm.qti.telephony.extcarrierpack version 7.1.1. On named Coolpad Defiant and T-Mobile Revvl Plus builds, any co-located app can invoke factory reset behavior without permissions, causing user data and installed apps to be removed.

Likely exposure

Exposure appears limited to the Coolpad Defiant cp3632a Android 7.1.1 build and T-Mobile Revvl Plus alchemy Android 7.1.1 build named in the CVE. Organizations are mainly exposed if these legacy devices remain in use, especially where users can install untrusted apps.

Exploitation context

The source bundle does not cite KEV listing or active exploitation. Abuse requires an app already present on the device. The issue bypasses normal Android restrictions because the vulnerable capability is exposed through a preinstalled platform app component.

Researcher notes

The public record is specific about vulnerable components and device builds, but the bundle provides no CVSS score, CWE, patch identifier, or exploitation evidence. Avoid generalizing to all Qualcomm, Coolpad, or Android 7.1.1 devices without additional source support.

Mitigation direction

  • Inventory fleets for the named Coolpad Defiant and T-Mobile Revvl Plus builds.
  • Check vendor, carrier, or firmware guidance for an official fix or update.
  • Retire or isolate affected legacy devices if no supported update exists.
  • Restrict installation of untrusted apps through MDM or enterprise policy.
  • Ensure user data is backed up or synced off-device.

Validation and detection

  • Confirm device model, Android build, and firmware against the CVE description.
  • Check whether com.qualcomm.qti.telephony.extcarrierpack versionCode 25 is installed.
  • Review the app manifest for the exported UiccReceiver component and permission protection.
  • Verify whether vendor or carrier firmware updates remove or protect the receiver.
  • Document any affected assets and compensating controls in device inventory.
Prepared
Confidence
high
Sources
4

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2018-15003 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
4Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
n/an/an/aListed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.