CVE 4.8 MEDIUM

Verkehrsauskunft Österreich SmartRide/cleVVVer/BusBahnBim AndroidManifest.xml improper export of android application components_CVE-2025-9135

4.8 / 10
MEDIUM
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P

Description

A vulnerability was detected in Verkehrsauskunft Österreich SmartRide, cleVVVer and BusBahnBim up to 12.1.1(258). The impacted element is an unknown function of the file AndroidManifest.xml. The manipulation results in improper export of android application components. The attack must be initiated from a local position. The exploit is now public and may be used. Upgrading to version 12.1.2(259) is sufficient to resolve this issue. Upgrading the affected component is recommended.

Basic Information

ID CVE-2025-9135
Source VulDB
Published Aug 19, 2025 at 11:02

Affected Product

Vendor Verkehrsauskunft Österreich
Product SmartRide
Version 12.1.1(258)
Affected Versions Verkehrsauskunft Österreich SmartRide 12.1.1(258)
Verkehrsauskunft Österreich cleVVVer 12.1.1(258)
Verkehrsauskunft Österreich BusBahnBim 12.1.1(258)

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.