PT-2025-40411 · Flock Safety · Bravo Edge Ai Compute Device+3

Gainsec

·

Published

2025-10-02

·

Updated

2026-04-22

·

CVE-2025-59405

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Flock Safety Peripheral version 7.38.3
Description The Flock Safety Peripheral application for Android contains a cleartext DataDog API key within its codebase. Attackers can recover the OAuth secret without special privileges by decompiling or inspecting the application binaries. This secret is intended to remain confidential and should not be embedded directly in client-side software. The application is installed on Falcon and Sparrow License Plate Readers and Bravo Edge AI Compute Devices.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2025-59405

Affected Products

Bravo Edge Ai Compute Device
Falcon License Plate Readers
Flock Safety Peripheral
Sparrow License Plate Readers