CVE-2012-3884

Airdroid - Authentication Bypass

Title source: rule

Description

AirDroid 1.0.4 beta implements authentication through direct transmission of a password hash over HTTP, which makes it easier for remote attackers to obtain access by sniffing the local wireless network and then replaying the authentication data.

Scores

EPSS 0.0031
EPSS Percentile 54.2%

Classification

CWE
CWE-287
Status draft

Affected Products (1)

airdroid/airdroid

Timeline

Published Jul 26, 2012
Tracked Since Feb 18, 2026