Skip to content
October 1, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Free Tools
    • CVSS 3.1 Calculator
    • Certificate Viewer
    • DNS Lookup
    • Encoder & Hash Generator
    • IP / Subnet Calculator
    • Whois Lookup
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
  • Home
  • Technique
  • This 90’s Encryption Backdoor Flaw Still Exists in Modern Devices
  • Technique

This 90’s Encryption Backdoor Flaw Still Exists in Modern Devices

Do Son July 5, 2021 6 minutes read
tech-crypto

A recently discovered issue in the encryption algorithm GEA-1, which is used to encrypt data connections in mobile phones, is ringing cybersecurity alarms as it affects many mobile devices. Even newer models of smartphones are said to be affected.

This newly detected but decades-old cybersecurity threat is not some highly sophisticated and creative approach in defeating security controls. It is also not an aggressive attack that overwhelms servers or installs malicious software in systems. It is a vulnerability that may or may not have been used by bad actors over the past decades.

An intentionally weak encryption algorithm?

The problem was first disclosed by a research team from Ruhr-Universität Bochum (RUB). After analyzing the encryption algorithm GEA-1, they concluded that it is remarkably easy to break. The team suggested that it could be designed to be deliberately weak to serve as a backdoor.

GEA-1 was introduced by the European Telecommunications Standards Institute (ETSI) in 1998 to provide 64-bit encryption for data traffic such as email sending and web data transmission. The problem is that the researchers discovered that this algorithm reportedly only offers 40-bit encryption. Also, the way this algorithm’s encryption keys are subdivided makes the encryption relatively easy to decrypt.

RUB researcher Dr. Christof Beierl said that this algorithm weakness could not have been coincidental or unwitting. “According to our experimental analysis, having six correct numbers in the German lottery twice in a row is about as likely as having these properties of the key occur by chance,” Beierl said.

GEA-1 does not pass current standards for reliable data encryption. At present, more advanced standards are being employed including GEA-3, GEA-4, Triple DES, RSA, Blowfish, Twofish, The Advanced Encryption Standard (AES), and Elliptic Curve Cryptography (ECC).

The researchers thought that the GEA-1 algorithm should have already disappeared several years ago. It should have ceased existing in modern mobile devices as early as 2013, with the emergence of digital mobile phone standards beyond GPRS. The GEA-1 algorithm is associated with the now obsolete GPRS or 2G standard. However, the group of researchers revealed that they found the algorithm in current Android and iOS mobile phones.

The researchers say that GEA-1 is being kept in modern devices as a backup encryption algorithm in some Android and iOS devices including the Huawei P9 Lite and iPhone XR. The standards for these mobile devices specifically ban support for GEA-1. That’s why it is surprising how the algorithm is being used as a backup.

Similar issue with GEA-2

The research team also evaluated the GEA-2 encryption algorithm and found similar issues. Gregor Leander, one of the researchers involved in the study, mused that this second-generation algorithm was likely an upgrade intended to address the weaknesses of its predecessor. “GEA-2 was hardly better, though,” Leander said. If it is any consolation, Leander noted that the security weakness of GEA-2 was likely not intentional.

The details of the study are presented in Cryptology ePrint Archive: Report 2021/819. “In contrast, for GEA-2 we did not discover the same intentional weakness. However, using a combination of algebraic techniques and list merging algorithms we are still able to break GEA-2 in time 245.1 GEA-2 evaluations. The main practical hurdle is the required knowledge of 1600 bytes of the keystream,” the report wrote.

Impact of the vulnerability

In an interview with The Register, Professor Matthew Green of the Johns Hopkins Information Security Institute inferred the seeming pattern of deliberately weak encryption standards from the European standards bodies from the 1990s through the 2000s. “I think this was unfortunate and probably did damage to people in the long run,” Green suggested.

This security weakness can be rather easy to exploit. A rogue phone mast, for example, can downgrade the data traffic encryption of nearby devices to GEA-1. Phones that support the GEA-1 and GEA-2 algorithms will be forced to downgrade their encryption if an attacker manages to exploit the vulnerability.

“There are devices called Stingrays that do this for law enforcement, but I doubt law enforcement are the only people who have access to this technology,” Green said. Stingrays can successfully snoop usernames, passwords, and other unencrypted or minimally protected data, as they imitate the functions of a cellular tower, thus tricking mobile devices into connecting to them.

Unfortunately, the researchers did not release a full list of devices that are affected by this newly discovered old cyber threat. Device specifications nowadays also do not mention anything about GEA-1 and GEA-2 support. It would be difficult to determine if a device can be manipulated into downgrading its data encryption to GEA-1 or GEA-2.

However, since this problem has already been made public, manufacturers are likely to release security patches or firmware updates to address the threat. To avoid becoming victims of cyber-attacks that leverage the GEA-1 and GEA-2 vulnerabilities, it is important for everyone to make sure that they update their software or firmware.

GEA-1 support cannot be disabled through the settings of a smartphone or by some other DIY procedures. The only way to get rid of it is through a firmware/software update, something only the device manufacturers can do. Device users cannot get rid of GEA-1 on their own. Reformatting or flashing a new firmware to their devices is not going to solve the problem.

No need to panic

Despite the potential for the vulnerability to be taken advantage of by cybercriminals, the RUB research team said that it no longer poses a significant threat. “Even though intelligence services and ministers of the interior understandably want such backdoors to exist, they are not at all useful,”  the researchers said.

The main concern about this newly unveiled security threat is that it may be used by government bodies to spy on individuals or organizations. As the researchers declared, there is little to be worried about when it comes to governments using weak encryption as a backdoor. “After all, they are not the only ones who can exploit these vulnerabilities, any other attackers can exploit them as well. Our research shows: once a backdoor is implemented, it is very difficult to remove it,” the research team explained.

However, the threat of cybercriminals exploiting the vulnerability for their felonious objectives remains. Device users are not helpless against these threats, though. The key solution is to make sure that the devices used are properly updated.

SHARE
Share on FacebookShare on XShare on LinkedInShare on TelegramShare on BlueskyShare on Mastodon

Search

Translation

CVE ALERTS
📈

EPSS Spike Alerts
Catch risk spikes before they make headlines.

🎯

Custom EPSS/CVSS
Set score thresholds to effectively filter noise.

🛡️

Exploit Intel
Real-world exploit signals beyond the KEV catalog.

🐙

GitHub Issues
Auto-create alert tickets without duplication.

📬

Weekly Digest
Clean summaries, eliminating email spam.

🏷️

Watchlist Groups
Tag vulnerabilities by team (Infra/AppSec/SOC).

🔀

Smart Routing
Route chat channels based on severity levels.

🚨

RBP Tracker
Early warning detection and tracking system.

Subscribe – $7/mo or try free for 14 days →

🚨 Active Exploits in the Wild

  • CVE-2026-100382CVSS 10.0
    Improper Neutralization of Special Elements used in an OS Command (\'OS Command Injection\') vulnerability in Wikimedia Foundation Mediawiki...
    Admin intel📅 Updated: Oct 1, 2026
  • CVE-2026-76504CVSS 9.8
    A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote...
    Admin intelCISA KEV📅 Added to KEV: Sep 30, 2026📅 Updated: Sep 30, 2026
  • CVE-2026-86950CVSS 8.8
    An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and...
    Admin intelCISA KEV📅 Added to KEV: Sep 29, 2026📅 Updated: Sep 29, 2026
  • CVE-2026-88772
    Memory overflow vulnerability leading to remote code execution or denial of service.
    Admin intelCISA KEV📅 Added to KEV: Sep 27, 2026📅 Updated: Sep 27, 2026
  • CVE-2026-88771
    Remote code execution due to improper input validation that can allow an unauthenticated attacker to execute arbitrary commands.
    Admin intelCISA KEV📅 Added to KEV: Sep 27, 2026📅 Updated: Sep 27, 2026
  • CVE-2026-65660CVSS 8.8
    Improper control of generation of code (\'code injection\') in Microsoft Office SharePoint allows an authorized attacker to execute...
    Admin intelCISA KEV📅 Added to KEV: Sep 25, 2026📅 Updated: Sep 25, 2026
  • CVE-2026-5430CVSS 10.0
    The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows...
    CISA KEV📅 Added to KEV: Sep 24, 2026
  • CVE-2026-71362CVSS 9.1
    Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could...
    CISA KEV📅 Added to KEV: Sep 24, 2026
Powered by CVE Watchtower

Critical Vulnerabilities

  • CVE-2026-75957CVSS 9.8
    The Ultimate Multisite – WordPress Multisite SaaS & WaaS Platform plugin for WordPress is vulnerable to Authentication Bypass...
    📅 Updated: Oct 1, 2026
  • CVE-2026-15989CVSS 9.8
    The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Privilege Escalation in...
    📅 Updated: Oct 1, 2026
  • CVE-2026-92966CVSS 9.1
    The The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin for WordPress is vulnerable...
    📅 Updated: Oct 1, 2026
  • CVE-2026-101148CVSS 10.0
    The BackupSheep WordPress Backup Plugin WordPress plugin through 1.8 does not properly validate its integration key, treating an...
    📅 Updated: Oct 1, 2026
  • CVE-2026-62329CVSS 9.8
    Vulnerability Type: CWE-1392: Use of Default Credentials Attack type: Unauthenticated remote Impact: Unauthenticated users can access the default...
    📅 Updated: Oct 1, 2026
  • CVE-2026-103264CVSS 9.3
    Fleet versions before 4.87.0 contain an authentication bypass vulnerability in the device API that accepts hostnames and hardware...
    📅 Updated: Oct 1, 2026
  • CVE-2026-103244CVSS 9.3
    ground-station versions before 0.8.0 contain an authentication bypass vulnerability in the setup.restore command that allows unauthenticated attackers to...
    📅 Updated: Oct 1, 2026
  • CVE-2026-57496CVSS 9.6
    ## REST Path Traversal Bypasses Token Redaction in netlicensing-mcp ### Summary The `netlicensing_get_product` MCP tool in `netlicensing-mcp` interpolates...
    📅 Updated: Oct 1, 2026
Powered by CVE Watchtower

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.