CVE-2025-45080

Published Jul 1, 2025

Last updated 2 months ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2025-45080 is a vulnerability found in the YONO SBI: Banking & Lifestyle app, version 1.23.36. The application uses unencrypted communications, which could allow attackers to perform man-in-the-middle (MITM) attacks. This vulnerability arises from the app transmitting sensitive banking and lifestyle data without encryption, exposing it to interception and manipulation. The vulnerability is due to the `android:usesCleartextTraffic="true"` setting in the application's manifest file. This setting permits the app to transmit data via unencrypted HTTP, even though Android OS security best practices typically disallow cleartext traffic by default. This can be exploited on public Wi-Fi or compromised networks, where attackers can observe or alter HTTP traffic, potentially compromising user login credentials, personal details, and financial transactions.

Description
Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.
Source
cve@mitre.org
NVD status
Rejected

Social media

Hype score
Not currently trending

References

Sources include official advisories and independent security research.