CVE-2025-63433
Xtooltech Xtool AnyScan Android Application 4.40.40 and prior uses a hardcoded cryptographic key and IV to decrypt update metadata. The key is stored as a static value within the application's code. An attacker with the ability to intercept network traffic can use this hardcoded key to decrypt, modify, and re-encrypt the update manifest, allowing them to direct the application to download a malicious update package.
Vendor
Product
CWE
Yayın Tarihi
2025-11-24 17:16:07
Güncelleme
2025-11-28 17:06:07
Source Identifier
cve@mitre.org
KEV Date Added
-