CVE-2025-63433 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

Xtooltech Xtool AnyScan Android Application 4.40.40 and prior uses a hardcoded cryptographic key and IV to decrypt update metadata. The key is stored as a stati…
Medium CVSS: 4.6

CVE-2025-63433

Xtooltech Xtool AnyScan Android Application 4.40.40 and prior uses a hardcoded cryptographic key and IV to decrypt update metadata. The key is stored as a static value within the application's code. An attacker with the ability to intercept network traffic can use this hardcoded key to decrypt, modify, and re-encrypt the update manifest, allowing them to direct the application to download a malicious update package.
Vendor
Xtooltech
Product
Xtool Anyscan
CWE
CWE-798
Yayın Tarihi
2025-11-24 17:16:07
Güncelleme
2025-11-28 17:06:07
Source Identifier
cve@mitre.org
KEV Date Added
-

Kategoriler

Referanslar