PT-2025-36018 · Unknown · Connectivity Service

Published

2025-06-01

·

Updated

2025-09-04

·

CVE-2025-26445

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions ConnectivityService (affected versions not specified)
Description A missing permission check in the offerNetwork function of ConnectivityService.java may lead to local information disclosure. Exploitation does not require user interaction or elevated privileges.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authorization

Weakness Enumeration

Related Identifiers

ASB-A-388828859
CVE-2025-26445

Affected Products

Connectivity Service