Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qcqv-64cg-9qm4

Опубликовано: 24 нояб. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 4.6

Описание

Xtooltech Xtool AnyScan Android Application 4.40.40 and prior is Missing SSL Certificate Validation. The application fails to properly validate the TLS certificate from its update server. An attacker on the same network can exploit this vulnerability by performing a Man-in-the-Middle (MITM) attack to intercept, decrypt, and modify traffic between the application and the update server. This serves as the basis for further attacks, including Remote Code Execution.

Xtooltech Xtool AnyScan Android Application 4.40.40 and prior is Missing SSL Certificate Validation. The application fails to properly validate the TLS certificate from its update server. An attacker on the same network can exploit this vulnerability by performing a Man-in-the-Middle (MITM) attack to intercept, decrypt, and modify traffic between the application and the update server. This serves as the basis for further attacks, including Remote Code Execution.

EPSS

Процентиль: 9%
0.00034
Низкий

4.6 Medium

CVSS3

Дефекты

CWE-599

Связанные уязвимости

CVSS3: 4.6
nvd
3 месяца назад

Xtooltech Xtool AnyScan Android Application 4.40.40 and prior is Missing SSL Certificate Validation. The application fails to properly validate the TLS certificate from its update server. An attacker on the same network can exploit this vulnerability by performing a Man-in-the-Middle (MITM) attack to intercept, decrypt, and modify traffic between the application and the update server. This serves as the basis for further attacks, including Remote Code Execution.

EPSS

Процентиль: 9%
0.00034
Низкий

4.6 Medium

CVSS3

Дефекты

CWE-599