Vulnerability Description
Sogexia Android App Compile Affected SDK v35, Max SDK 32 and fixed in v36, was discovered to contain hardcoded encryption keys in the encryption_helper.dart file
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sogexia | Sogexia | 35 |
Related Weaknesses (CWE)
References
- https://medium.com/@sudosu01/information-disclosure-hardcoded-encryption-keys-fcThird Party Advisory
- https://www.linkedin.com/in/umanhonlengabrielNot Applicable
FAQ
What is CVE-2025-63289?
CVE-2025-63289 is a vulnerability with a CVSS score of 9.1 (CRITICAL). Sogexia Android App Compile Affected SDK v35, Max SDK 32 and fixed in v36, was discovered to contain hardcoded encryption keys in the encryption_helper.dart file
How severe is CVE-2025-63289?
CVE-2025-63289 has been rated CRITICAL with a CVSS base score of 9.1/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2025-63289?
Check the references section above for vendor advisories and patch information. Affected products include: Sogexia Sogexia.