Xtooltech Xtool AnyScan Android Application 4.40.40 and prior is Missing SSL Certificate Validation. The application fails to properly validate the TLS certificate from its update server. An attacker on the same network can exploit this vulnerability by performing a Man-in-the-Middle (MITM) attack to intercept, decrypt, and modify traffic between the application and the update server. This serves as the basis for further attacks, including Remote Code Execution.
References
| Link | Resource |
|---|---|
| https://github.com/ab3lson/cve-references/tree/master/CVE-2025-63432 | Third Party Advisory |
| https://www.nowsecure.com/blog/2025/07/16/remote-code-execution-discovered-in-xtool-anyscan-app-risks-to-phones-and-vehicles/ | Exploit Third Party Advisory |
Configurations
History
28 Nov 2025, 17:04
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/ab3lson/cve-references/tree/master/CVE-2025-63432 - Third Party Advisory | |
| References | () https://www.nowsecure.com/blog/2025/07/16/remote-code-execution-discovered-in-xtool-anyscan-app-risks-to-phones-and-vehicles/ - Exploit, Third Party Advisory | |
| CPE | cpe:2.3:a:xtooltech:xtool_anyscan:*:*:*:*:*:android:*:* | |
| First Time |
Xtooltech
Xtooltech xtool Anyscan |
24 Nov 2025, 19:15
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-599 | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 4.6 |
24 Nov 2025, 17:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-11-24 17:16
Updated : 2025-11-28 17:04
NVD link : CVE-2025-63432
Mitre link : CVE-2025-63432
CVE.ORG link : CVE-2025-63432
JSON object : View
Products Affected
xtooltech
- xtool_anyscan
CWE
CWE-599
Missing Validation of OpenSSL Certificate
