A security vulnerability has been detected in Tomofun Furbo Mobile App up to 7.57.0a on Android. This affects an unknown part of the component Authentication Token Handler. The manipulation leads to insecure storage of sensitive information. It is possible to launch the attack on the physical device. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
History

Thu, 23 Oct 2025 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google android
Tomofun
Tomofun furbo Mobile App
Vendors & Products Google
Google android
Tomofun
Tomofun furbo Mobile App

Tue, 14 Oct 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 12 Oct 2025 20:45:00 +0000

Type Values Removed Values Added
Description A security vulnerability has been detected in Tomofun Furbo Mobile App up to 7.57.0a on Android. This affects an unknown part of the component Authentication Token Handler. The manipulation leads to insecure storage of sensitive information. It is possible to launch the attack on the physical device. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Title Tomofun Furbo Mobile App Authentication Token sensitive information
Weaknesses CWE-200
CWE-922
References
Metrics cvssV2_0

{'score': 2.1, 'vector': 'AV:L/AC:L/Au:N/C:P/I:N/A:N/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 2.4, 'vector': 'CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 2.4, 'vector': 'CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 2.4, 'vector': 'CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2025-10-18T21:27:53.120Z

Reserved: 2025-10-11T18:32:59.727Z

Link: CVE-2025-11645

cve-icon Vulnrichment

Updated: 2025-10-14T14:02:23.058Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-10-12T21:15:33.303

Modified: 2025-10-14T19:36:59.730

Link: CVE-2025-11645

cve-icon Redhat

No data.