WRITEUP

WRITEUP
Exploit for CVE-2025-63433 - Xtooltech Xtool AnyScan <4.40.40 - Code Injection
AI Analysis

This repository contains detailed technical writeups for multiple CVEs in the Xtool AnyScan Android Application, including CVE-2025-63433, which involves a hardcoded cryptographic key used for update metadata decryption. The writeup provides in-depth analysis of the vulnerability, affected components, and the exploit chain leading to Remote Code Execution (RCE).

Attack Type
other
Complexity
moderate
Reliability
theoretical
MITRE ATT&CK
T1189 - Drive-by Compromise T1553 - Subvert Trust Controls
Loading exploit code...
Download ZIP Password: eip
Vulnerability
CVE-2025-63433
Xtooltech Xtool AnyScan <4.40.40 - Code Injection
MEDIUM
CVSS 4.6