CVE-2025-63823

CRITICAL

My Safetipin Android Application 5.2.1 - Unauthenticated Authentication Bypass via Hardcoded OTP Credentials

Title source: llm
STIX 2.1

Description

My Safetipin Android Application 5.2.1 contains Hardcoded credentials in the authentication module, which allows remote attackers to bypass authentication and gain unauthorized access to user accounts via predictable OTP values.

Scores

CVSS v3 9.8
EPSS 0.0044
EPSS Percentile 36.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-798
Status published
Published Aug 05, 2026
Tracked Since Aug 06, 2026