Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Airdroid

First CVE: Jul 26, 2012Active for: 14 yearsTotal CVEs: 8

Airdroid provides a remote-access and device-management application for mobile platforms that enables wireless control and file synchronization across connected devices. The recurring vulnerability surface clusters around the application's cross-device authentication and data-handling mechanisms, with exposures in improper authentication, information disclosure, cross-site scripting, and input validation that reflect the trust and connectivity model underpinning remote access tooling. Public exploit code has an elevated tendency to become available for vulnerabilities in this product; defenders should prioritize patching releases and restrict network exposure of management interfaces. Current severity, exploitation activity, and vulnerability counts are shown alongside this summary.

FAUCET AI Generated
8
Total CVEs
More Total CVEs than 90% of tracked vendors
2.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 80% of tracked vendors
5.5
Avg CVSS Score
Higher Avg CVSS Score than 22% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Airdroid over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 26, 2012
13 years ago
Most Recent CVE
Mar 6, 2019
2,697 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (8 CVEs).

8 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2019-9599HIGH
The AirDroid application through 4.2.1.6 for Android allows remote attackers to cause a denial of service (service crash) via many simultaneous sdctl/comm/lite_auth/ requests.
Mar 6, 20197.541NOYES
CVE-2012-3885HIGH
The default configuration of AirDroid 1.0.4 beta uses a four-character alphanumeric password, which makes it easier for remote attackers to obtain access via a brute-force attack.
Jul 26, 20127.522NONO
CVE-2012-3884MEDIUM
AirDroid 1.0.4 beta implements authentication through direct transmission of a password hash over HTTP, which makes it easier for remote attackers to obtain access by sniffing the
Jul 26, 20125.019NONO
CVE-2013-0134MEDIUM
Cross-site scripting (XSS) vulnerability in the web interface in AirDroid allows remote attackers to inject arbitrary web script or HTML via a crafted text message that is transmit
Apr 9, 20134.318NONO
CVE-2012-3888MEDIUM
The login implementation in AirDroid 1.0.4 beta allows remote attackers to bypass a multiple-login protection mechanism by modifying a pass value within JSON data.
Jul 26, 20125.018NONO
CVE-2012-3887MEDIUM
AirDroid before 1.0.7 beta uses a cleartext base64 format for data transfer that is documented as an "Encrypted Transmission" feature, which allows remote attackers to obtain sensi
Jul 26, 20125.018NONO
CVE-2012-3886MEDIUM
AirDroid 1.0.4 beta uses the MD5 algorithm for values in the checklogin key parameter and 7bb cookie, which makes it easier for remote attackers to obtain cleartext data by sniffin
Jul 26, 20125.018NONO
CVE-2015-5661MEDIUM
The SAND STUDIO AirDroid application 1.1.0 and earlier for Android mishandles implicit intents, which allows attackers to obtain sensitive information via a crafted application.
Oct 18, 20154.314NONO
View all 8 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products8 CVEs
75%
25%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network1 (12.5%)
Unknown7 (87.5%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low1 (12.5%)
High0 (0.0%)
Unknown7 (87.5%)
User Interaction
None1 (12.5%)
Unknown7 (87.5%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None1 (12.5%)
Unknown7 (87.5%)

Exploit Exposure

Signals from CVEs in this vendor scope (8 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
12.5% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Airdroid.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Airdroid — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Airdroid's Products

View all 3 CNAs →

Top CWEs