CVE-2012-3887: Airdroid
Medium severity, CVSS 5.0. EPSS: 1.3% chance of exploitation in the next 30 days.
AirDroid before 1.0.7 beta uses a cleartext base64 format for data transfer that is documented as an "Encrypted Transmission" feature, which allows remote attackers to obtain sensitive information by sniffing the local wireless network, as demonstrated by the SMS message content sent to the sdctl/sms/send/single/ URI.
Affected products
- Airdroid Airdroid: up to and including 1.0.6; version 1.0.1 only; version 1.0.2 only; version 1.0.3 only; version 1.0.4 only; version 1.0.5 only
Published 2012-07-26. Last modified 2026-06-16.