CVE-2025-5500

MEDIUM

ZhenShi Mibro Fit App 1.6.3.17499 - Info Disclosure

Title source: llm
STIX 2.1

Description

A flaw has been found in ZhenShi Mibro Fit App 1.6.3.17499 on Android. This impacts an unknown function of the file AndroidManifest.xml of the component com.xiaoxun.xunoversea.mibrofit. This manipulation causes improper export of android application components. The attack requires local access. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

References (5)

Core 5
Core References
Permissions Required, VDB Entry vdb-entry
https://vuldb.com/?id.323234
Permissions Required, VDB Entry signature permissions-required
https://vuldb.com/?ctiid.323234
Permissions Required, VDB Entry third-party-advisory
https://vuldb.com/?submit.637921

Scores

CVSS v3 5.3
EPSS 0.0012
EPSS Percentile 2.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-926
Status published
Products (1)
ZhenShi/Mibro Fit App 1.6.3.17499
Published Sep 09, 2025
Tracked Since Feb 18, 2026