PT-2025-47946 · Xtooltech · Xtool Anyscan

Published

2025-11-24

·

Updated

2025-12-01

·

CVE-2025-63432

CVSS v3.1

4.6

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Xtooltech Xtool AnyScan Android Application versions 4.40.40 and prior
Description The Xtooltech Xtool AnyScan Android Application does not properly validate TLS certificates from its update server. This allows an attacker on the same network to perform a Man-in-the-Middle (MITM) attack, intercepting, decrypting, and modifying traffic between the application and the update server. This can lead to further attacks, including Remote Code Execution.
Recommendations Update the Xtooltech Xtool AnyScan Android Application to a version newer than 4.40.40.

Exploit

Fix

RCE

Weakness Enumeration

Related Identifiers

CVE-2025-63432

Affected Products

Xtool Anyscan