Vulnerability Description
operations/attestation/AttestationTask.kt in the Tangem SDK before 5.18.3 for Android has a logic flow in offline wallet attestation (genuineness check) that causes verification results to be disregarded during the first scan of a card. Exploitation may not have been possible.
CVSS Score
LOW
Related Weaknesses (CWE)
References
- https://github.com/tangem/tangem-sdk-android/commit/24588188fdb51ed469cd59d2c595
- https://github.com/tangem/tangem-sdk-android/releases/tag/release-app_5.18-409
- https://tangem.com/en/blog/post/app-update/
FAQ
What is CVE-2025-27839?
CVE-2025-27839 is a vulnerability with a CVSS score of 3.2 (LOW). operations/attestation/AttestationTask.kt in the Tangem SDK before 5.18.3 for Android has a logic flow in offline wallet attestation (genuineness check) that causes verification results to be disregar...
How severe is CVE-2025-27839?
CVE-2025-27839 has been rated LOW with a CVSS base score of 3.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-27839?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.