The sofa housekeeping APK application has a general design defect (Remote horse farming or other operations)
Rt
After the "sofa Guest Manager" APK application is installed, you can directly control the device through the Internet. You can remotely install the APK and perform other operations on the operation interface remotely (without any permission verification)
You can scan a wide range of IP segments to obtain devices.
Case:
http://222.248.56.16:8888/http://223.19.42.235:8888/http://223.17.153.117:8888/http://218.250.119.242:8888/http://218.250.13.210:8888/http://218.102.100.201:8888/http://124.244.205.32:8888/http://124.244.200.65:8888/http://119.247.251.59:8888/http://119.246.202.29:8888/http://113.255.109.104:8888/http://112.120.152.29:8888/http://58.153.215.205:8888/http://42.3.203.182:8888/http://42.2.174.246:8888/http://42.2.33.253:8888/http://1.64.245.18:8888/http://113.255.109.104:8888/http://113.254.43.186:8888/
Solution:
Add permission verification.