Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-63433

Опубликовано: 24 нояб. 2025
Источник: nvd
CVSS3: 4.6
EPSS Низкий

Описание

Xtooltech Xtool AnyScan Android Application 4.40.40 and prior uses a hardcoded cryptographic key and IV to decrypt update metadata. The key is stored as a static value within the application's code. An attacker with the ability to intercept network traffic can use this hardcoded key to decrypt, modify, and re-encrypt the update manifest, allowing them to direct the application to download a malicious update package.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:xtooltech:xtool_anyscan:*:*:*:*:*:android:*:*
Версия до 4.40.40 (включая)

EPSS

Процентиль: 8%
0.00029
Низкий

4.6 Medium

CVSS3

Дефекты

CWE-798

Связанные уязвимости

CVSS3: 4.6
github
2 месяца назад

Xtooltech Xtool AnyScan Android Application 4.40.40 and prior uses a hardcoded cryptographic key and IV to decrypt update metadata. The key is stored as a static value within the application's code. An attacker with the ability to intercept network traffic can use this hardcoded key to decrypt, modify, and re-encrypt the update manifest, allowing them to direct the application to download a malicious update package.

EPSS

Процентиль: 8%
0.00029
Низкий

4.6 Medium

CVSS3

Дефекты

CWE-798