Xtooltech Xtool AnyScan Android Application 4.40.40 and prior is Missing SSL Certificate Validation. The application fails to properly validate the TLS certificate from its update server. An attacker on the same network can exploit this vulnerability by performing a Man-in-the-Middle (MITM) attack to intercept, decrypt, and modify traffic between the application and the update server. This serves as the basis for further attacks, including Remote Code Execution.
Metrics
Affected Vendors & Products
References
History
Mon, 24 Nov 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-599 | |
| Metrics |
cvssV3_1
|
Mon, 24 Nov 2025 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Xtooltech Xtool AnyScan Android Application 4.40.40 and prior is Missing SSL Certificate Validation. The application fails to properly validate the TLS certificate from its update server. An attacker on the same network can exploit this vulnerability by performing a Man-in-the-Middle (MITM) attack to intercept, decrypt, and modify traffic between the application and the update server. This serves as the basis for further attacks, including Remote Code Execution. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published: 2025-11-24T00:00:00.000Z
Updated: 2025-11-24T18:17:11.303Z
Reserved: 2025-10-27T00:00:00.000Z
Link: CVE-2025-63432
Updated: 2025-11-24T18:17:00.459Z
Status : Awaiting Analysis
Published: 2025-11-24T17:16:07.510
Modified: 2025-11-25T22:16:16.690
Link: CVE-2025-63432
No data.