CVE-2025-61113

TalkTalk 3.3.6 Android App contains improper access control vulnerabilities in multiple API endpoints. By modifying request parameters, attackers may obtain sensitive user information (such as device identifiers and birthdays) and access private group information, including join credentials. Successful exploitation may result in privacy breaches and unauthorized access to restricted resources.
Configurations

No configuration.

History

30 Oct 2025, 21:15

Type Values Removed Values Added
CWE CWE-284
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5

30 Oct 2025, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-10-30 16:15

Updated : 2025-10-30 21:15


NVD link : CVE-2025-61113

Mitre link : CVE-2025-61113

CVE.ORG link : CVE-2025-61113


JSON object : View

Products Affected

No product.

CWE
CWE-284

Improper Access Control