Vulnerability Description
The Flock Safety DetectionProcessing com.flocksafety.android.objects application 6.35.33 for Android (installed on Falcon and Sparrow License Plate Readers and Bravo Edge AI Compute Devices) bundles a Java Keystore (flock_rye.bks) along with its hardcoded password (flockhibiki17) in its code. The keystore contains a private key.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Flocksafety | Flock Safety | 6.35.33 |
Related Weaknesses (CWE)
References
- https://gainsec.com/2025/09/27/fly-by-device-2-the-falcon-sparrow-gated-wirelessExploitThird Party Advisory
- https://gainsec.com/wp-content/uploads/2025/09/Root-from-the-Coop-Device-3_-RootExploitThird Party Advisory
- https://www.flocksafety.com/productsProduct
- https://www.flocksafety.com/products/license-plate-readersProduct
FAQ
What is CVE-2025-59407?
CVE-2025-59407 is a vulnerability with a CVSS score of 9.8 (CRITICAL). The Flock Safety DetectionProcessing com.flocksafety.android.objects application 6.35.33 for Android (installed on Falcon and Sparrow License Plate Readers and Bravo Edge AI Compute Devices) bundles a...
How severe is CVE-2025-59407?
CVE-2025-59407 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2025-59407?
Check the references section above for vendor advisories and patch information. Affected products include: Flocksafety Flock Safety.