PT-2026-25615 · Undefined · Undefined

Fxizenta

+1

·

Publicado

2026-03-16

·

Atualizado

2026-03-16

·

CVE-2026-4218

CVSS v3.1

2.5

Baixa

VetorAV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions myAEDES App versions through 1.18.4
Description A flaw exists in myAEDES App on Android that allows information disclosure. The issue is related to the manipulation of the AUTH KEY argument within an unknown function of the file aedes/me/beta/utils/EngageBayUtils.java of the aedes.me.beta component. This issue is only exploitable with local access and is considered difficult to exploit. The exploit is publicly available. The vendor was notified but did not respond.
Recommendations Versions through 1.18.4 should be updated when a fix is available. As a temporary workaround, consider restricting access to the aedes.me.beta component to minimize the risk of exploitation.

Exploit

Correção

Information Disclosure

Improper Access Control

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-4218

Produtos afetados

Undefined