CVE-2025-63433 – Xtooltech Xtool AnyScan Cryptographic Key Weakness
CVE ID : CVE-2025-63433
Published : Nov. 24, 2025, 5:16 p.m. | 2 hours, 6 minutes ago
Description : Xtooltech Xtool AnyScan Android Application 4.40.40 and prior uses a hardcoded cryptographic key and IV to decrypt update metadata. The key is stored as a static value within the application’s code. An attacker with the ability to intercept network traffic can use this hardcoded key to decrypt, modify, and re-encrypt the update manifest, allowing them to direct the application to download a malicious update package.
Severity: 4.6 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more…