Impact
The vulnerability arises from hardcoded credentials embedded in the authentication module of My Safetipin Android Application version 5.2.1. Because the OTP values are predictable, an attacker who can reach the application remotely may bypass normal authentication and log in as any user, thereby gaining unauthorized access to sensitive personal information and potentially performing malicious actions within the app. This flaw allows a complete compromise of user account integrity and confidentiality.
Affected Systems
The affected system is the My Safetipin Android Application, version 5.2.1, available on Android devices such as those installed from the Google Play Store under the package identifier com.safetipin.mysafetipin.
Risk and Exploitability
The CVE is not listed in CISA KEV, and the EPSS score is <1%, indicating a very low but non-zero probability of exploitation. Nonetheless, the authentication bypass represents a critical vulnerability that could be exploited remotely if an attacker can obtain the predictable OTP sequence. The CVSS score of 9.8 reflects the high impact of unauthorized access to user account data and potential malicious actions within the app.
OpenCVE Enrichment