TROYANOSYVIRUS
Retour aux CVEs

CVE-2025-63432

MEDIUM
4.6

Description

Xtooltech Xtool AnyScan Android Application 4.40.40 and prior is Missing SSL Certificate Validation. The application fails to properly validate the TLS certificate from its update server. An attacker on the same network can exploit this vulnerability by performing a Man-in-the-Middle (MITM) attack to intercept, decrypt, and modify traffic between the application and the update server. This serves as the basis for further attacks, including Remote Code Execution.

Details CVE

Score CVSS v3.14.6
SeveriteMEDIUM
Vecteur CVSSCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
Vecteur d'attaqueNETWORK
ComplexiteLOW
Privileges requisLOW
Interaction utilisateurREQUIRED
Publie11/24/2025
Derniere modification11/28/2025
Sourcenvd
Observations honeypot0

Produits affectes

xtooltech:xtool_anyscan

Faiblesses (CWE)

CWE-599

Correlations IOC

Aucune correlation enregistree

This product uses data from the NVD API but is not endorsed or certified by the NVD.