Impact
An issue in EcoOnline EHS (com.airsweb.v10) for Android, version 0.2.499, allows a remote attacker to obtain sensitive information and execute arbitrary code by exploiting a flaw in the AndroidManifest.xml component. This vulnerability enables the attacker to run code with the application's privileges, potentially compromising device security and leaking confidential data. The impact is direct code execution and exposure of sensitive data within the mobile environment.
Affected Systems
Devices running the EcoOnline EHS application, Android version not specified but the flaw appears in the app package com.airsweb.v10 version 0.2.499. The vulnerability is specific to this application and affects all users who install or run this version.
Risk and Exploitability
The CVE admits remote code execution, which is a high‑severity risk. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, but the lack of neutralization steps combined with the ability to execute arbitrary code suggests a significant threat. The likely attack path involves a remote attacker manipulating or replacing the AndroidManifest.xml component to obtain elevated privileges. The risk remains elevated until a vendor patch or remediation is applied.
OpenCVE Enrichment