Sand Studio · Airdroid · CVE-2019-9599
**Name of the Vulnerable Software and Affected Versions**
AirDroid versions through 4.2.1.6
**Description**
The issue allows remote attackers to cause a denial of service, resulting in a service crash. This can be achieved by sending many simultaneous requests to the `sdctl/comm/lite auth/` endpoint.
**Recommendations**
For AirDroid versions through 4.2.1.6, consider restricting access to the `sdctl/comm/lite auth/` endpoint to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.