CVE-2025-63435

Source
https://cve.org/CVERecord?id=CVE-2025-63435
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-63435.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-63435
Published
2025-11-24T17:16:08.283Z
Modified
2026-03-13T03:40:46.212779Z
Severity
  • 4.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
Summary
[none]
Details

Xtooltech Xtool AnyScan Android Application 4.40.40 is Missing Authentication for Critical Function. The server-side endpoint responsible for serving update packages for the application does not require any authentication. This allows an unauthenticated remote attacker to freely download official update packages..

References

Affected packages

Git /

Affected ranges

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-63435.json"
unresolved_ranges
[
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "4.40.40"
            }
        ]
    }
]