github.com
https://github.com/ab3lson/cve-references/tree/master/CVE-2025-63432 CVE-2025-63432
MEDIUM
Record summary
CVE-2025-63432 has a selected CVSS score of 4.6 (medium).
Description
Xtooltech Xtool AnyScan Android Application 4.40.40 and prior is Missing SSL Certificate Validation. The application fails to properly validate the TLS certificate from its update server. An attacker on the same network can exploit this vulnerability by performing a Man-in-the-Middle (MITM) attack to intercept, decrypt, and modify traffic between the application and the update server. This serves as the basis for further attacks, including Remote Code Execution.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Nov 24, 2025 · Source: CVE List