Junglewise Threat Intelligence

CVE-2025-67264: Doogee Note59 series OS command injection in EngineerMode

CVE-2025-67264 · Severity: high · CVSS 7.8 · Published 2026-01-23

Executive brief

A security flaw in several Doogee smartphone models allows a local user or malicious application to execute unauthorized commands. This occurs because a diagnostic 'EngineerMode' tool was incorrectly left accessible in the device software. An attacker could exploit this to gain elevated privileges and take control of the device's operating system.

Technical details

An OS command injection vulnerability exists in the com.sprd.engineermode component of Doogee Note59, Note59 Pro, and Note59 Pro+ devices running Android 15. The vulnerability stems from an incomplete patch of a previous flaw (CVE-2025-31710), where the 'Adb shell' activity was inadvertently re-enabled or left accessible. A local attacker can exploit this by interacting with the EngineerMode activity to initiate a reverse shell (e.g., using netcat commands). This allows for arbitrary code execution and privilege escalation on the device. The issue is reportedly due to the manufacturer using older VNDK components or configurations that reintroduced the vulnerable activity into the Android 15 firmware.

Affected products

  • Doogee Note59 Android 15
  • Doogee Note59 Pro Android 15
  • Doogee Note59 Pro+ Android 15

Timeline

  • 2025-01-23: disclosed
  • 2026-01-23: advisory

References