Security Advisory

CVE-2025-65827

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2025-12-10 00:00:00
Last updated 2025-12-11 20:12:46
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

The mobile application is configured to allow clear text traffic to all domains and communicates with an API server over HTTP. As a result, an adversary located "upstream" can intercept the traffic, inspect its contents, and modify the requests in transit. TThis may result in a total compromise of the user's account if the attacker intercepts a request with active authentication tokens or cracks the MD5 hash sent on login.