The Lotus Cars Android app (com.lotus.carsdomestic.intl) 1.2.8 contains an exported component, PushDeepLinkActivity, which is accessible without authentication via ADB or malicious apps. This poses a risk of unintended access to application internals and can cause denial of service or logic abuse.
Metrics
Affected Vendors & Products
References
History
Sat, 16 Aug 2025 21:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Google
Google android Lotuscars Lotuscars android App |
|
Vendors & Products |
Google
Google android Lotuscars Lotuscars android App |
Fri, 15 Aug 2025 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-284 CWE-400 |
|
Metrics |
cvssV3_1
|
Thu, 14 Aug 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The Lotus Cars Android app (com.lotus.carsdomestic.intl) 1.2.8 contains an exported component, PushDeepLinkActivity, which is accessible without authentication via ADB or malicious apps. This poses a risk of unintended access to application internals and can cause denial of service or logic abuse. | |
References |
|

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-08-15T16:43:53.429Z
Reserved: 2025-06-16T00:00:00.000Z
Link: CVE-2025-50861

Updated: 2025-08-15T16:43:47.424Z

Status : Awaiting Analysis
Published: 2025-08-14T20:15:31.910
Modified: 2025-08-15T17:15:32.197
Link: CVE-2025-50861

No data.