CVE-2025-63823

critical

Description

My Safetipin Android Application 5.2.1 contains Hardcoded credentials in the authentication module, which allows remote attackers to bypass authentication and gain unauthorized access to user accounts via predictable OTP values.

References

https://play.google.com/store/apps/details?id=com.safetipin.mysafetipin

https://github.com/Leoccc98/cve-reports/blob/main/advisories/CVE-2025-63823/README.md

Details

Source: Mitre, NVD

Published: 2026-08-05

Updated: 2026-08-05

Risk Information

CVSS v2

Base Score: 7.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

Severity: High

CVSS v3

Base Score: 9.8

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: Critical