CVE-2025-63432

Xtooltech Xtool AnyScan Android Application 4.40.40 and prior is Missing SSL Certificate Validation. The application fails to properly validate the TLS certificate from its update server. An attacker on the same network can exploit this vulnerability by performing a Man-in-the-Middle (MITM) attack to intercept, decrypt, and modify traffic between the application and the update server. This serves as the basis for further attacks, including Remote Code Execution.
Configurations

Configuration 1 (hide)

cpe:2.3:a:xtooltech:xtool_anyscan:*:*:*:*:*:android:*:*

History

28 Nov 2025, 17:04

Type Values Removed Values Added
References () https://github.com/ab3lson/cve-references/tree/master/CVE-2025-63432 - () https://github.com/ab3lson/cve-references/tree/master/CVE-2025-63432 - Third Party Advisory
References () https://www.nowsecure.com/blog/2025/07/16/remote-code-execution-discovered-in-xtool-anyscan-app-risks-to-phones-and-vehicles/ - () https://www.nowsecure.com/blog/2025/07/16/remote-code-execution-discovered-in-xtool-anyscan-app-risks-to-phones-and-vehicles/ - Exploit, Third Party Advisory
CPE cpe:2.3:a:xtooltech:xtool_anyscan:*:*:*:*:*:android:*:*
First Time Xtooltech
Xtooltech xtool Anyscan

24 Nov 2025, 19:15

Type Values Removed Values Added
CWE CWE-599
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.6

24 Nov 2025, 17:16

Type Values Removed Values Added
New CVE

Information

Published : 2025-11-24 17:16

Updated : 2025-11-28 17:04


NVD link : CVE-2025-63432

Mitre link : CVE-2025-63432

CVE.ORG link : CVE-2025-63432


JSON object : View

Products Affected

xtooltech

  • xtool_anyscan
CWE
CWE-599

Missing Validation of OpenSSL Certificate