PT-2025-30287 · Unknown+1 · Com.Enflick.Android.Tn2Ndline+1

Edward Warren

·

Publicado

2025-07-21

·

Atualizado

2025-07-21

·

CVE-2025-43976

CVSS v3.1

5.5

Média

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions com.enflick.android.tn2ndLine versions through 24.17.1.0
Description The com.enflick.android.tn2ndLine application for Android allows any installed application, without requiring permissions, to initiate phone calls without user interaction. This is achieved by sending a crafted intent to the com.enflick.android.TextNow.activities.DialerActivity component.
Recommendations Update com.enflick.android.tn2ndLine to a version later than 24.17.1.0.

Exploit

Correção

Missing Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-43976

Produtos afetados

Textnow
Com.Enflick.Android.Tn2Ndline