Impact
The vulnerability allows an attacker to retrieve a hardcoded API key embedded in the GV-Eye Android application. Because the key can be extracted from the application package, malicious actors could gain unauthorized access to the payment relay service, potentially initiating fraudulent transactions or compromising financial data.
Affected Systems
This flaw affects the GeoVision Inc. GV-Eye Android application, specifically versions 3.6.0 and 3.7.2.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity, while the EPSS score is not provided and the vulnerability is not yet listed in the CISA KEV catalog. Attackers can exploit it by reverse‑engineering the APK, extracting the API key, and reusing it to call the payment API. The vulnerability relies on an easily accessible client‑side credential, making exploitation straightforward for anyone able to decompile the application.
OpenCVE Enrichment