4.8
/ 10
MEDIUM
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Description
A vulnerability was found in Boquan DotWallet App 2.15.2 on Android and classified as problematic. Affected by this issue is some unknown functionality of the file AndroidManifest.xml of the component com.boquanhash.dotwallet. The manipulation leads to improper export of android application components. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Basic Information
ID
CVE-2025-8524
Source
VulDB
Published
Aug 4, 2025 at 20:02
Modified
Aug 4, 2025 at 20:17
Affected Product
Vendor
Boquan
Product
DotWallet App
Version
2.15.2
Affected Versions
Boquan DotWallet App 2.15.2