PT-2025-40412 · Flock Safety · Flock Safety Pisco+3

Gainsec

·

Published

2025-10-02

·

Updated

2025-10-24

·

CVE-2025-59406

CVSS v3.1

6.2

Medium

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Flock Safety Pisco application version 6.21.11
Description The Flock Safety Pisco application for Android contains a cleartext Auth0 client secret within its codebase. Attackers can recover this OAuth secret without elevated privileges by decompiling or inspecting the application binaries. The secret is intended to be confidential and should not be embedded directly in client-side software. The application is installed on Falcon and Sparrow License Plate Readers and Bravo Edge AI Compute Devices.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Cleartext Transmission of Sensitive Information

Weakness Enumeration

Related Identifiers

CVE-2025-59406

Affected Products

Bravo Edge Ai Compute Device
Falcon License Plate Readers
Flock Safety Pisco
Sparrow License Plate Readers