FRP/Factory Reset Vulnerability on Android 10–12 (MobiWire/Mobigo Devices): No Firmware Fix Available — Upgrade to Android 14+ Required
Android
AndroidiOS
If you're managing MobiWire Mobigo devices running Android 10, 11, or 12, you may encounter a Factory Reset Protection (FRP) vulnerability that allows users to bypass MDM enrollment and escape Esper management. This article explains why this occurs, what devices are affected, and how to resolve it.
Understand the vulnerability
Devices running Android 10, 11, or 12 contain platform-level FRP and recovery-mode factory reset vulnerabilities that Google has not patched. Because Google stopped approving new software updates for these Android versions, device manufacturers—including MobiWire—cannot ship firmware fixes. This means affected devices cannot be patched and remain vulnerable to MDM bypass.
This is an Android platform issue, not a problem with Esper. It affects all MDM solutions on these Android versions.
Check your device's Android version
- In the Esper Console, go to Devices & Groups.
- Click the device name.
- Go to Device Info and check the OS Version field.
- If the version is Android 10, 11, or 12, the device is affected and cannot be patched.
Resolve the vulnerability through hardware replacement
The only way to resolve this vulnerability is to replace affected devices with units running Android 14 or higher. MobiWire introduced additional security layers starting with Android 14 that address MDM-bypass vulnerabilities. On Android 15 or 16 devices, MobiWire also provides an API that allows you to programmatically disable factory reset from Recovery Mode.
- Contact your hardware procurement team or OEM contact at MobiWire to identify replacement devices running Android 14 or higher.
- Request specific SKUs for Mobigo or equivalent devices on Android 14–16 that include:
- The additional Android 14+ security layer for MDM-bypass vulnerability mitigation
- Recovery-reset disable API support (available on Android 15 or 16 depending on device model)
- Confirm these details directly with MobiWire before purchasing.
- Once you receive replacement devices, re-provision them through Esper using your standard enrollment workflow (QR code, Zero-Touch, KME, or ABM).
- If your devices support Android 15 or 16 with the OEM API, work with your development team to integrate the MobiWire-provided API into your application to disable factory reset from Recovery Mode.
- Verify that replacement devices are enrolled in Esper, your Blueprint is applied, and the device status shows as Online in Devices & Groups.
Interim risk mitigation (before hardware replacement)
While you work on hardware replacement, you can reduce—but not eliminate—the attack surface using Esper features:
- Enable kiosk lockdown to restrict user access to system settings.
- Use Blueprint policies to disable physical buttons if applicable.
- Apply Device Policy restrictions to limit user actions.
These measures reduce exposure but do not fix the underlying vulnerability. Plan for hardware replacement as your primary mitigation strategy.
Still need help?
If you have questions about which devices are affected, need help confirming your device's Android version, or want to discuss interim mitigation options, contact Esper Support.
Please sign in to leave a comment.
Comments
0 comments