CVE-2025-65827CRITICAL 9.1EPSS p13.2%

CVE-2025-65827CVE-2025-65827

Description

The mobile application is configured to allow clear text traffic to all domains and communicates with an API server over HTTP. As a result, an adversary located "upstream" can intercept the traffic, inspect its contents, and modify the requests in transit. TThis may result in a total compromise of the user's account if the attacker intercepts a request with active authentication tokens or cracks the MD5 hash sent on login.

Scoring

CVSS 3.19.1 (CRITICAL)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
EPSS0.23% probability of exploitation · percentile 13.2% · 2026-06-19T12:03:05Z
Published2025-12-10
Last modified2025-12-30

Underlying weaknesses· 1

CWE-319

References

  1. https://gist.github.com/dead1nfluence/4dffc239b4a460f41a03345fd8e5feb5#file-clear-text-traffic-enabled-md
  2. https://github.com/dead1nfluence/Meatmeet-Pro-Vulnerabilities/blob/main/Mobile-Application/Clear-Text-Traffic-Enabled.md

1

TypeTargetConfidenceTier
WeaknessCleartext Transmission of Sensitive Informationcwe-3190%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
CVE-2025-65830
CVE
CVE-2025-58587
CVE
CVE-2025-30023
CVE
CVE-2025-55057
CVE
CVE-2025-64127
CVE
CVE-2025-52692
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.