PT-2025-47947 · Xtooltech · Xtool Anyscan

Published

2025-11-24

·

Updated

2025-12-01

·

CVE-2025-63433

CVSS v3.1

4.6

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Xtooltech Xtool AnyScan Android Application versions 4.40.40 and prior
Description The Xtooltech Xtool AnyScan Android Application utilizes a hardcoded cryptographic key and Initialization Vector (IV) for decrypting update metadata. This key is embedded as a static value within the application’s code. An attacker intercepting network traffic can exploit this to decrypt, modify, and re-encrypt the update manifest, potentially directing the application to download and install a malicious update package.
Recommendations Update to a newer version of Xtooltech Xtool AnyScan Android Application that does not use the hardcoded cryptographic key.

Exploit

Fix

Using Hardcoded Credentials

Weakness Enumeration

Related Identifiers

CVE-2025-63433

Affected Products

Xtool Anyscan