Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-63432

Опубликовано: 24 нояб. 2025
Источник: nvd
CVSS3: 4.6
EPSS Низкий

Описание

Xtooltech Xtool AnyScan Android Application 4.40.40 and prior is Missing SSL Certificate Validation. The application fails to properly validate the TLS certificate from its update server. An attacker on the same network can exploit this vulnerability by performing a Man-in-the-Middle (MITM) attack to intercept, decrypt, and modify traffic between the application and the update server. This serves as the basis for further attacks, including Remote Code Execution.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:xtooltech:xtool_anyscan:*:*:*:*:*:android:*:*
Версия до 4.40.40 (включая)

EPSS

Процентиль: 12%
0.00039
Низкий

4.6 Medium

CVSS3

Дефекты

CWE-599

Связанные уязвимости

CVSS3: 4.6
github
3 месяца назад

Xtooltech Xtool AnyScan Android Application 4.40.40 and prior is Missing SSL Certificate Validation. The application fails to properly validate the TLS certificate from its update server. An attacker on the same network can exploit this vulnerability by performing a Man-in-the-Middle (MITM) attack to intercept, decrypt, and modify traffic between the application and the update server. This serves as the basis for further attacks, including Remote Code Execution.

EPSS

Процентиль: 12%
0.00039
Низкий

4.6 Medium

CVSS3

Дефекты

CWE-599