CVE-2019-13096
CRITICALTronLink Wallet 2.2.0 - Cleartext Storage of Sensitive Information in Keystore
Title source: llmDescription
TronLink Wallet 2.2.0 stores user wallet keystore in plaintext and places them in insecure storage. An attacker can read and reuse the user keystore of a valid user via /data/data/com.tronlink.wallet/shared_prefs/<wallet-name>.xml to gain unauthorized access.
References (2)
Core 2
Core References
Exploit, Third Party Advisory x_refsource_misc
https://pastebin.com/raw/J9B8Lh0j
Exploit, Third Party Advisory x_refsource_misc
https://pastebin.com/raw/08REmV1X
Scores
CVSS v3
9.8
EPSS
0.0114
EPSS Percentile
62.5%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-312
Status
published
Products (1)
tronlink/wallet
2.2.0
Published
Jul 22, 2019
Tracked Since
Feb 18, 2026