Airdroid provides a remote-access and device-management application for mobile platforms that enables wireless control and file synchronization across connected devices. The recurring vulnerability surface clusters around the application's cross-device authentication and data-handling mechanisms, with exposures in improper authentication, information disclosure, cross-site scripting, and input validation that reflect the trust and connectivity model underpinning remote access tooling. Public exploit code has an elevated tendency to become available for vulnerabilities in this product; defenders should prioritize patching releases and restrict network exposure of management interfaces. Current severity, exploitation activity, and vulnerability counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Airdroid over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-9599HIGH The AirDroid application through 4.2.1.6 for Android allows remote attackers to cause a denial of service (service crash) via many simultaneous sdctl/comm/lite_auth/ requests. | Mar 6, 2019 | 7.5 | 41 | NO | YES |
CVE-2012-3885HIGH The default configuration of AirDroid 1.0.4 beta uses a four-character alphanumeric password, which makes it easier for remote attackers to obtain access via a brute-force attack. | Jul 26, 2012 | 7.5 | 22 | NO | NO |
CVE-2012-3884MEDIUM AirDroid 1.0.4 beta implements authentication through direct transmission of a password hash over HTTP, which makes it easier for remote attackers to obtain access by sniffing the | Jul 26, 2012 | 5.0 | 19 | NO | NO |
CVE-2013-0134MEDIUM Cross-site scripting (XSS) vulnerability in the web interface in AirDroid allows remote attackers to inject arbitrary web script or HTML via a crafted text message that is transmit | Apr 9, 2013 | 4.3 | 18 | NO | NO |
CVE-2012-3888MEDIUM The login implementation in AirDroid 1.0.4 beta allows remote attackers to bypass a multiple-login protection mechanism by modifying a pass value within JSON data. | Jul 26, 2012 | 5.0 | 18 | NO | NO |
CVE-2012-3887MEDIUM AirDroid before 1.0.7 beta uses a cleartext base64 format for data transfer that is documented as an "Encrypted Transmission" feature, which allows remote attackers to obtain sensi | Jul 26, 2012 | 5.0 | 18 | NO | NO |
CVE-2012-3886MEDIUM AirDroid 1.0.4 beta uses the MD5 algorithm for values in the checklogin key parameter and 7bb cookie, which makes it easier for remote attackers to obtain cleartext data by sniffin | Jul 26, 2012 | 5.0 | 18 | NO | NO |
CVE-2015-5661MEDIUM The SAND STUDIO AirDroid application 1.1.0 and earlier for Android mishandles implicit intents, which allows attackers to obtain sensitive information via a crafted application. | Oct 18, 2015 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Airdroid.
Media articles that mention a CVE ID that affects a product developed by Airdroid — matched by CVE ID, not by vendor name.