An OS command injection vulnerability in the com.sprd.engineermode component in Doogee Note59, Note59 Pro, and Note59 Pro+ allows a local attacker to execute arbitrary code and escalate privileges via the EngineerMode ADB shell, due to incomplete patching of CVE-2025-31710

Project Subscriptions

Vendors Products
Note59 Firmware Subscribe
Note59 Pro Subscribe
Note59 Pro+ Subscribe
Note59 Pro\+ Subscribe
Note59 Pro\+ Firmware Subscribe
Note59 Pro Firmware Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 11 Feb 2026 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Doogee note59 Firmware
Doogee note59 Pro\+
Doogee note59 Pro\+ Firmware
Doogee note59 Pro Firmware
CPEs cpe:2.3:h:doogee:note59:-:*:*:*:*:*:*:*
cpe:2.3:h:doogee:note59_pro:-:*:*:*:*:*:*:*
cpe:2.3:h:doogee:note59_pro\+:-:*:*:*:*:*:*:*
cpe:2.3:o:doogee:note59_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:doogee:note59_pro\+_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:doogee:note59_pro_firmware:-:*:*:*:*:*:*:*
Vendors & Products Doogee note59 Firmware
Doogee note59 Pro\+
Doogee note59 Pro\+ Firmware
Doogee note59 Pro Firmware

Mon, 26 Jan 2026 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 26 Jan 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-78
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Mon, 26 Jan 2026 12:00:00 +0000

Type Values Removed Values Added
First Time appeared Doogee
Doogee note59
Doogee note59 Pro
Doogee note59 Pro+
Vendors & Products Doogee
Doogee note59
Doogee note59 Pro
Doogee note59 Pro+

Fri, 23 Jan 2026 20:15:00 +0000

Type Values Removed Values Added
Description An OS command injection vulnerability in the com.sprd.engineermode component in Doogee Note59, Note59 Pro, and Note59 Pro+ allows a local attacker to execute arbitrary code and escalate privileges via the EngineerMode ADB shell, due to incomplete patching of CVE-2025-31710
References

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-01-26T15:56:07.316Z

Reserved: 2025-12-08T00:00:00.000Z

Link: CVE-2025-67264

cve-icon Vulnrichment

Updated: 2026-01-26T15:55:37.863Z

cve-icon NVD

Status : Analyzed

Published: 2026-01-23T20:15:53.790

Modified: 2026-02-11T19:26:36.910

Link: CVE-2025-67264

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-01-26T11:54:15Z

Weaknesses