CVE-2025-59403CRITICAL 9.8EPSS p58.8%

CVE-2025-59403CVE-2025-59403

Description

The Flock Safety Android Collins application (aka com.flocksafety.android.collins) 6.35.31 for Android lacks authentication. It is responsible for the camera feed on Falcon, Sparrow, and Bravo devices, but exposes administrative API endpoints on port 8080 without authentication. Endpoints include but are not limited to: /reboot, /logs, /crashpack, and /adb/enable. This results in multiple impacts including denial of service (DoS) via /reboot, information disclosure via /logs, and remote code execution (RCE) via /adb/enable. The latter specifically results in adb being started over TCP without debugging confirmation, providing an attacker in the LAN/WLAN with shell access.

Scoring

CVSS 3.19.8 (CRITICAL)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS1.02% probability of exploitation · percentile 58.8% · 2026-06-19T12:03:05Z
Published2025-10-02
Last modified2025-11-24

Underlying weaknesses· 1

CWE-749

References

  1. https://gainsec.com/2025/09/27/fly-by-device-2-the-falcon-sparrow-gated-wireless-rce-camera-feed-dos-information-disclosure-and-more/
  2. https://gainsec.com/wp-content/uploads/2025/09/Root-from-the-Coop-Device-3_-Root-Shell-on-Flock-Safetys-Bravo-Compute-Box-GainSec.pdf
  3. https://www.flocksafety.com/products
  4. https://www.flocksafety.com/products/license-plate-readers

1

TypeTargetConfidenceTier
WeaknessExposed Dangerous Method or Functioncwe-7490%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
CVE-2025-59407
CVE
CVE-2025-65826
CVE
CVE-2025-25270
CVE
CVE-2025-0593
CVE
CVE-2025-54497
CVE
CVE-2025-40805
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.