« Back to list

Xtooltech

Xtooltech Xtool Anyscan: vulnerabilities and CVEs

Xtooltech Xtool Anyscan has 4 published vulnerabilities, 4 of them in the last 12 months. 0 are rated critical and 0 are listed by CISA as actively exploited.

CVEs4
Last 12 months4
Critical0
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2025-63435Medium (4.3)0.36%—Nov 24, 2025
Xtooltech Xtool AnyScan Android Application 4.40.40 is Missing Authentication for Critical Function. The server-side endpoint responsible for serving update packages for the application does not require any…
CVE-2025-63434High (8.8)0.31%—Nov 24, 2025
The update mechanism in Xtooltech Xtool AnyScan Android Application 4.40.40 and prior is insecure. The application downloads and extracts update packages containing executable code without performing a cryptographic…
CVE-2025-63433Medium (4.6)0.19%—Nov 24, 2025
Xtooltech Xtool AnyScan Android Application 4.40.40 and prior uses a hardcoded cryptographic key and IV to decrypt update metadata. The key is stored as a static value within the application's code. An attacker with the…
CVE-2025-63432Medium (4.6)0.17%—Nov 24, 2025
Xtooltech Xtool AnyScan Android Application 4.40.40 and prior is Missing SSL Certificate Validation. The application fails to properly validate the TLS certificate from its update server. An attacker on the same network…

🎯 How it gets exploited (ATT&CK techniques)

  1. T1195.002 Compromise Software Supply Chain1
  2. T1210 Exploitation of Remote Services1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.