📦 Xtool Anyscan

by Xtooltech

🔍 What is Xtool Anyscan?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-63434

HIGH CVSS 8.8 Nov 24, 2025

This vulnerability allows remote code execution on Android devices running Xtooltech Xtool AnyScan app versions 4.40.40 and earlier. An attacker who can intercept or manipulate update traffic can serv...

CVE-2025-63435

MEDIUM CVSS 4.3 Nov 24, 2025

The Xtooltech Xtool AnyScan Android application version 4.40.40 has a missing authentication vulnerability in its update server endpoint. This allows unauthenticated remote attackers to download offic...

CVE-2025-63432

MEDIUM CVSS 4.6 Nov 24, 2025

The Xtooltech Xtool AnyScan Android application fails to validate TLS certificates, allowing attackers on the same network to perform man-in-the-middle attacks. This vulnerability enables interception...

CVE-2025-63433

MEDIUM CVSS 4.6 Nov 24, 2025

The Xtooltech Xtool AnyScan Android application uses hardcoded cryptographic keys to decrypt update metadata, allowing attackers who intercept network traffic to manipulate update manifests and redire...