CVE-2025-63433 – Xtooltech Xtool AnyScan Cryptographic Key Weakness

CVE ID : CVE-2025-63433

Published : Nov. 24, 2025, 5:16 p.m. | 2 hours, 6 minutes ago

Description : Xtooltech Xtool AnyScan Android Application 4.40.40 and prior uses a hardcoded cryptographic key and IV to decrypt update metadata. The key is stored as a static value within the application’s code. An attacker with the ability to intercept network traffic can use this hardcoded key to decrypt, modify, and re-encrypt the update manifest, allowing them to direct the application to download a malicious update package.

Severity: 4.6 | MEDIUM

Visit the link for more details, such as CVSS details, affected products, timeline, and more… 

نوشته های مشابه