Executive brief
Vivo PcSuite, a tool used to manage mobile devices from a computer, contains a vulnerability where a security confirmation prompt can be bypassed. This could allow an unauthorized person on the same local network to establish a connection to the software without the user's explicit approval. While it does not directly lead to data theft, it undermines the security controls intended to prevent unauthorized device interaction.
Technical details
A vulnerability in Vivo PcSuite (versions prior to 6.2.0) allows for the bypass of a connection confirmation pop-up. The issue is categorized as a reliance on untrusted inputs in a security decision (CWE-807). An attacker located on the same adjacent network (e.g., local Wi-Fi) can trigger specific features without the required user interaction or authorization. This bypass affects the integrity of the connection process but is not reported to impact confidentiality or availability directly. The vulnerability is resolved in PcSuite version 6.2.0.
Affected products
- Vivo PcSuite Versions below 6.2.0
Timeline
- 2026-06-12: disclosed
- 2026-06-12: patched: Fixed in version 6.2.0
- 2026-06-12: advisory