PT-2025-47948 · Xtooltech · Xtool Anyscan

Published

2025-11-24

·

Updated

2025-11-24

·

CVE-2025-63434

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Xtooltech Xtool AnyScan Android Application versions prior to 4.40.40
Description The application’s update process is flawed because it downloads and extracts update packages with executable code without verifying their integrity or authenticity. An attacker controlling the update metadata could deliver a malicious package that the application accepts, extracts, and executes, potentially resulting in arbitrary code execution.
Recommendations Update to version 4.40.40 or later.

Exploit

Fix

RCE

Weakness Enumeration

Related Identifiers

CVE-2025-63434

Affected Products

Xtool Anyscan