github.com
https://github.com/tangem/tangem-sdk-android/commit/24588188fdb51ed469cd59d2c595128c1fe63b07 CVE-2025-27839
LOW
Record summary
CVE-2025-27839 has a selected CVSS score of 3.2 (low).
Description
operations/attestation/AttestationTask.kt in the Tangem SDK before 5.18.3 for Android has a logic flow in offline wallet attestation (genuineness check) that causes verification results to be disregarded during the first scan of a card. Exploitation may not have been possible.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 10, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Default status: unaffected | CVE List | Before 5.18.3 | affected |
References
4github.com
https://github.com/tangem/tangem-sdk-android/releases/tag/release-app_5.18-409 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-27839 tangem.com
https://tangem.com/en/blog/post/app-update