Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-63434

Опубликовано: 24 нояб. 2025
Источник: nvd
CVSS3: 8.8
EPSS Низкий

Описание

The update mechanism in Xtooltech Xtool AnyScan Android Application 4.40.40 and prior is insecure. The application downloads and extracts update packages containing executable code without performing a cryptographic integrity or authenticity check on their contents. An attacker who can control the update metadata can serve a malicious package, which the application will accept, extract, and later execute, leading to arbitrary code execution.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:xtooltech:xtool_anyscan:*:*:*:*:*:android:*:*
Версия до 4.40.40 (включая)

EPSS

Процентиль: 12%
0.0004
Низкий

8.8 High

CVSS3

Дефекты

CWE-494

Связанные уязвимости

CVSS3: 8.8
github
3 месяца назад

The update mechanism in Xtooltech Xtool AnyScan Android Application 4.40.40 and prior is insecure. The application downloads and extracts update packages containing executable code without performing a cryptographic integrity or authenticity check on their contents. An attacker who can control the update metadata can serve a malicious package, which the application will accept, extract, and later execute, leading to arbitrary code execution.

EPSS

Процентиль: 12%
0.0004
Низкий

8.8 High

CVSS3

Дефекты

CWE-494