Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xx5r-8vrj-6x6c

Опубликовано: 24 нояб. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 4.3

Описание

Xtooltech Xtool AnyScan Android Application 4.40.40 is Missing Authentication for Critical Function. The server-side endpoint responsible for serving update packages for the application does not require any authentication. This allows an unauthenticated remote attacker to freely download official update packages..

Xtooltech Xtool AnyScan Android Application 4.40.40 is Missing Authentication for Critical Function. The server-side endpoint responsible for serving update packages for the application does not require any authentication. This allows an unauthenticated remote attacker to freely download official update packages..

EPSS

Процентиль: 27%
0.00094
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-306

Связанные уязвимости

CVSS3: 4.3
nvd
2 месяца назад

Xtooltech Xtool AnyScan Android Application 4.40.40 is Missing Authentication for Critical Function. The server-side endpoint responsible for serving update packages for the application does not require any authentication. This allows an unauthenticated remote attacker to freely download official update packages..

EPSS

Процентиль: 27%
0.00094
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-306