Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-5471

Опубликовано: 03 апр. 2026
Источник: nvd
CVSS3: 3.3
CVSS2: 1.7
EPSS Низкий

Описание

A vulnerability was detected in Investory Toy Planet Trouble App up to 1.5.5 on Android. Impacted is an unknown function of the file assets/google-services-desktop.json of the component app.investory.toyfactory. The manipulation of the argument current_key results in use of hard-coded cryptographic key . The attack must be initiated from a local position. The exploit is now public and may be used.

EPSS

Процентиль: 1%
0.00011
Низкий

3.3 Low

CVSS3

1.7 Low

CVSS2

Дефекты

CWE-320

Связанные уязвимости

CVSS3: 3.3
github
4 дня назад

A vulnerability was detected in Investory Toy Planet Trouble App up to 1.5.5 on Android. Impacted is an unknown function of the file assets/google-services-desktop.json of the component app.investory.toyfactory. The manipulation of the argument current_key results in use of hard-coded cryptographic key . The attack must be initiated from a local position. The exploit is now public and may be used.

EPSS

Процентиль: 1%
0.00011
Низкий

3.3 Low

CVSS3

1.7 Low

CVSS2

Дефекты

CWE-320