CVE-2019-13096

CRITICAL

TronLink Wallet 2.2.0 - Cleartext Storage of Sensitive Information in Keystore

Title source: llm
STIX 2.1

Description

TronLink Wallet 2.2.0 stores user wallet keystore in plaintext and places them in insecure storage. An attacker can read and reuse the user keystore of a valid user via /data/data/com.tronlink.wallet/shared_prefs/<wallet-name>.xml to gain unauthorized access.

References (2)

Core 2
Core References
Exploit, Third Party Advisory x_refsource_misc
https://pastebin.com/raw/J9B8Lh0j
Exploit, Third Party Advisory x_refsource_misc
https://pastebin.com/raw/08REmV1X

Scores

CVSS v3 9.8
EPSS 0.0114
EPSS Percentile 62.5%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-312
Status published
Products (1)
tronlink/wallet 2.2.0
Published Jul 22, 2019
Tracked Since Feb 18, 2026