Impact
The Ticket Ryutsu Center Android application stores a hard‑coded credential that can be extracted by an attacker. The credential is used to obtain an API key that the application uses to communicate with its back‑end services. This represents a classic credential compromise (CWE-798) and allows an attacker who learns the key to authenticate to those services as if they were a legitimate app user. The impact includes potential confidentiality and integrity violations of data accessed through the API, and could also enable denial of service if the attacker sends abusive requests.
Affected Systems
The vulnerability is present in the Ticket Ryutsu Center application distributed by Wavedash Co., Ltd. The information given does not specify a version number, so all current releases that have not been patched are considered affected.
Risk and Exploitability
The CVSS score for the issue is 5.1, indicating a medium severity. Because the flaw is derived from hard‑coded credentials inside the application code, an attacker can obtain the necessary data by reverse‑engineering the APK or extracting the binary resources. This requires only local access to the application package on a device or the ability to analyze the released software; no network intrusion is required. The vulnerability is not listed in the CISA KEV catalog, suggesting that known exploit activity is not publicly reported at this time.
OpenCVE Enrichment