Multiple HTC products contain a flaw that may lead to an unauthorized information disclosure. The issue is triggered due to the 'WifiConfiguration::toString()' method returning WiFi credentials of stored networks in cleartext.
Classification
Location:
Remote / Network Access,
Mobile Phone / Hand-held Device
Attack Type:
Information Disclosure
Impact:
Loss of Confidentiality
Solution:
Upgrade
Exploit:
Exploit Public
Disclosure:
Vendor Verified,
Coordinated Disclosure
Solution
Upgrade to the latest version as of 2012-01-31 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds. Consult the vendor advisory to find the upgrade for your phone.