Xtooltech
Xtooltech Xtool Anyscan: vulnerabilities and CVEs
Xtooltech Xtool Anyscan has 4 published vulnerabilities, 4 of them in the last 12 months. 0 are rated critical and 0 are listed by CISA as actively exploited.
CVEs4
Last 12 months4
Critical0
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-63435 | Medium (4.3) | 0.36% | — | Nov 24, 2025 | Xtooltech Xtool AnyScan Android Application 4.40.40 is Missing Authentication for Critical Function. The server-side endpoint responsible for serving update packages for the application does not require any… |
| CVE-2025-63434 | High (8.8) | 0.31% | — | Nov 24, 2025 | The update mechanism in Xtooltech Xtool AnyScan Android Application 4.40.40 and prior is insecure. The application downloads and extracts update packages containing executable code without performing a cryptographic… |
| CVE-2025-63433 | Medium (4.6) | 0.19% | — | Nov 24, 2025 | Xtooltech Xtool AnyScan Android Application 4.40.40 and prior uses a hardcoded cryptographic key and IV to decrypt update metadata. The key is stored as a static value within the application's code. An attacker with the… |
| CVE-2025-63432 | Medium (4.6) | 0.17% | — | Nov 24, 2025 | Xtooltech Xtool AnyScan Android Application 4.40.40 and prior is Missing SSL Certificate Validation. The application fails to properly validate the TLS certificate from its update server. An attacker on the same network… |
🎯 How it gets exploited (ATT&CK techniques)
Number of CVEs of this technology mapped to each exploitation or primary-impact technique.