Tronlink is a cryptocurrency wallet application whose disclosed vulnerabilities center on sensitive-data handling defects, specifically the cleartext storage of sensitive information and inadvertent insertion of credentials into log files. These weakness classes reflect the operational challenges of managing private keys and authentication material in client-side wallet software; current severity, exploitation, and exposure details are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Tronlink over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-13096CRITICAL TronLink Wallet 2.2.0 stores user wallet keystore in plaintext and places them in insecure storage. An attacker can read and reuse the user keystore of a valid user via /data/data/ | Jul 22, 2019 | 9.8 | 28 | NO | NO |
CVE-2019-13098MEDIUM The user password via the registration form of TronLink Wallet 2.2.0 is stored in the log when the class CreateWalletTwoActivity is called. Other authenticated users can read it in | Jul 22, 2019 | 6.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Tronlink.
Media articles that mention a CVE ID that affects a product developed by Tronlink — matched by CVE ID, not by vendor name.