bitcoinVend icon indicating copy to clipboard operation
bitcoinVend copied to clipboard

AutoConnect lib has XSS injection vulnerability through Wi-Fi beacon frame. (CVE-2025-50740) which impacts your project.

Open AbhijithAJ opened this issue 3 months ago • 0 comments

Your device is vulnerable to CVE-2025-50740 and I suggest you fix this to ensure security of the project/device.

Impact: A malicious user in vicinity could use this issue to

  • Inject malicious code into the mobile from which user is trying to configure the device.
  • Make connection to his own wi-fi network to keep the device in his control.

AbhijithAJ avatar Sep 06 '25 08:09 AbhijithAJ