PT-2026-30224 · Unknown · Mobile App+1
Published
2026-04-03
·
Updated
2026-04-03
·
CVE-2025-10681
CVSS v3.1
8.6
High
| AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Storage credentials in mobile app and device firmware (affected versions not specified)
Description
The mobile app and device firmware contain hardcoded storage credentials that do not adequately limit end user permissions and do not expire within a reasonable timeframe. This may allow unauthorized access to production storage containers.
Recommendations
Remove the hardcoded storage credentials from the mobile app and device firmware. Implement appropriate permission limits for end users. Ensure storage credentials expire within a reasonable timeframe.
Fix
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Device Firmware
Mobile App