Xtooltech's vulnerability footprint concentrates on its Xtool Anyscan diagnostic and scanning product, with a durable signal centered on supply-chain and credential-handling weaknesses including code download without integrity verification, missing authentication on critical functions, improper OpenSSL certificate validation, and hard-coded credentials. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Xtooltech over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-63434HIGH The update mechanism in Xtooltech Xtool AnyScan Android Application 4.40.40 and prior is insecure. The application downloads and extracts update packages containing executable code | Nov 24, 2025 | 8.8 | 27 | NO | NO |
CVE-2025-63433MEDIUM Xtooltech Xtool AnyScan Android Application 4.40.40 and prior uses a hardcoded cryptographic key and IV to decrypt update metadata. The key is stored as a static value within the a | Nov 24, 2025 | 4.6 | 19 | NO | NO |
CVE-2025-63432MEDIUM Xtooltech Xtool AnyScan Android Application 4.40.40 and prior is Missing SSL Certificate Validation. The application fails to properly validate the TLS certificate from its update | Nov 24, 2025 | 4.6 | 19 | NO | NO |
CVE-2025-63435MEDIUM Xtooltech Xtool AnyScan Android Application 4.40.40 is Missing Authentication for Critical Function. The server-side endpoint responsible for serving update packages for the applic | Nov 24, 2025 | 4.3 | 18 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Xtooltech.
Media articles that mention a CVE ID that affects a product developed by Xtooltech — matched by CVE ID, not by vendor name.