HIGH

CVE-2025-63822

2026-08-05 CVSS v3.1
CVSS
8.1

Description

SirenGPS Android Application 2.19.44 is vulnerable to Incorrect Access Control. An authenticated attacker can manipulate user identifier parameters to bypass authorization controls and gain unauthorized READ and WRITE access to other users' personal information. The API fails to validate that the requesting user is authorized to access the target user's data.

Weakness (CWE)

CWE-284 Improper Access Control

EPSS Score

0.22%
Probability of exploitation in next 30 days
13th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE