CVE-2024-41955

MEDIUM NUCLEI

Mobile Security Framework < 4.0.5 - Open Redirect in Authentication View

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2024-41955 has a Nuclei detection template available — see the Nuclei card below for the Shodan/FOFA recon queries.

Description

Mobile Security Framework (MobSF) is a security research platform for mobile applications in Android, iOS and Windows Mobile. An open redirect vulnerability exist in MobSF authentication view. Update to MobSF v4.0.5.

Nuclei Templates (1)

Open Redirect in Login Redirect - MobSF
MEDIUMVERIFIEDby Farish
FOFA: MobSF

Scores

CVSS v3 5.2
EPSS 0.0092
EPSS Percentile 55.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-601
Status published
Products (2)
opensecurity/mobile_security_framework < 4.0.5
pypi/mobsf 0 - 4.0.5PyPI
Published Jul 31, 2024
Tracked Since Feb 18, 2026