CVE-2025-2342 | IROAD X5 Mobile App up to 5.2.5 on Android API Endpoint hard-coded credentials (Duplicate CVE-2025-30109)
A vulnerability classified as critical has been found in IROAD X5 Mobile App up to 5.2.5 on Android. Affected is an unknown function of the component API Endpoint. The manipulation leads to hard-coded credentials.
This vulnerability is traded as CVE-2025-2342. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
It is recommended to apply restrictive firewalling.
The vendor was contacted early about this disclosure but did not respond in any way. It looks like this entry got a duplicate CVE-2025-30109 assigned.