PT-2025-33626 · Vowifi+2 · Vowifi+2

Published

2025-08-18

·

Updated

2025-08-23

·

CVE-2025-31715

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: vowifi (affected versions not specified)
Description: A command injection issue exists in the vowifi service due to improper input validation. This could lead to remote escalation of privilege without requiring additional execution privileges. The vulnerability impacts devices running Mocor5/Android 8.1/9.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Related Identifiers

CVE-2025-31715

Affected Products

Android
Mocor5
Vowifi