Impact
An issue in EcoOnline EHS (com.airsweb.v10) for Android, version 0.2.499, allows a remote attacker to obtain sensitive information and execute arbitrary code by exploiting a flaw in the AndroidManifest.xml component. This vulnerability enables the attacker to run code with the application's privileges, potentially compromising device security and leaking confidential data. The impact is direct code execution and exposure of sensitive data within the mobile environment.
Affected Systems
Devices running the EcoOnline EHS application, Android version not specified but the flaw appears in the app package com.airsweb.v10 version 0.2.499. The vulnerability is specific to this application and affects all users who install or run this version.
Risk and Exploitability
With a CVSS score of 9.8, the CVE permits remote code execution, representing a critical risk. The EPSS score is less than 1% and the vulnerability is not listed in the CISA KEV catalog, yet the lack of mitigation and the ability to execute arbitrary code point to a significant threat. The likely attack path involves a remote attacker manipulating or replacing the AndroidManifest.xml component to obtain elevated privileges. The risk remains elevated until a vendor patch or remediation is applied.
OpenCVE Enrichment