Impact
The vulnerability arises from hardcoded credentials embedded in the authentication module of My Safetipin Android Application version 5.2.1. Because the OTP values are predictable, an attacker who can reach the application remotely may bypass normal authentication and log in as any user, thereby gaining unauthorized access to sensitive personal information and potentially performing malicious actions within the app. This flaw allows a complete compromise of user account integrity and confidentiality.
Affected Systems
The affected system is the My Safetipin Android Application, version 5.2.1, available on Android devices such as those installed from the Google Play Store under the package identifier com.safetipin.mysafetipin.
Risk and Exploitability
The CVE is not listed in CISA KEV and no EPSS score is available, indicating limited publicly known exploitation data. Nonetheless, the authentication bypass represents a critical vulnerability that could be exploited remotely if an attacker can obtain the predictable OTP sequence. The lack of a public exploit does not diminish the risk to users of the affected application, as the flaw inherently allows direct access to user accounts without standard credential verification.
OpenCVE Enrichment