CVE-2019-13098 describes a vulnerability in TronLink Wallet 2.2.0 on Android where user passwords entered during registration are logged in plain text. This allows other authenticated users or, on older Android versions, any installed application to read the password from the device logs. Rated Medium severity (CVSS 6.5), the vulnerability has a high impact on confidentiality due to the exposure of sensitive user credentials, but requires local access or a malicious application. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.2.0CPE matchmatch criteria | cpe:2.3:a:tronlink:wallet:2.2.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.