Xtooltech Xtool AnyScan Android Application 4.40.40 is Missing Authentication for Critical Function. The server-side endpoint responsible for serving update packages for the application does not require any authentication. This allows an unauthenticated remote attacker to freely download official update packages..
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NXtooltech Xtool Anyscan
APPXtooltech≤ 4.40.40
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
Related vulnerabilities
CVE-2025-63434HIGH8.8same product
The update mechanism in Xtooltech Xtool AnyScan Android Application 4.40.40 and prior is insecure. The applica...
CVE-2025-63432MEDIUM4.6same product
Aplikacja Android Xtooltech Xtool AnyScan w wersji 4.40.40 i wcześniejszych nie weryfikuje certyfikatów SSL. A...
CVE-2025-63433MEDIUM4.6same product
Aplikacja Xtooltech Xtool AnyScan na Androida w wersji 4.40.40 i wcześniejszych używa zakodowanego na stałe kl...