Chinese handset manufacturer ZTE has confirmed that a security vulnerability is present in the Android-based ZTE Score M smartphone. The phone includes an application, /system/bin/sync_agent, with a hard-coded password that can, now, be easily found on the internet.
The application, when run with the password, gives the user root access to the device and therefore could be used to completely take over a phone.
The link for this article located at H Security is no longer available.