Skip to main content

Vendor/product archive

xtooltech / xtool_anyscan CVEs

Beta · best-effort

4 CVEs tagged to xtooltech / xtool_anyscan0 Critical, 1 High, 3 Medium, 0 Low, 0 Unrated.

CVE-2025-63435

Published Nov 24, 2025

Xtooltech Xtool AnyScan Android Application 4.40.40 is Missing Authentication for Critical Function. The server-side endpoint responsible for serving update packages for the appli…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-63434

Published Nov 24, 2025

The update mechanism in Xtooltech Xtool AnyScan Android Application 4.40.40 and prior is insecure. The application downloads and extracts update packages containing executable cod…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-63433

Published Nov 24, 2025

Xtooltech Xtool AnyScan Android Application 4.40.40 and prior uses a hardcoded cryptographic key and IV to decrypt update metadata. The key is stored as a static value within the…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-63432

Published Nov 24, 2025

Xtooltech Xtool AnyScan Android Application 4.40.40 and prior is Missing SSL Certificate Validation. The application fails to properly validate the TLS certificate from its update…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-4 of 4 CVEsPage 1 of 1