CVE-2017-11129: Stashcat Heinekingmedia

Critical severity, CVSS 9.8. EPSS: 1.1% chance of exploitation in the next 30 days.

An issue was discovered in heinekingmedia StashCat through 1.7.5 for Android. The keystore is locked with a hard-coded password. Therefore, everyone with access to the keystore can read the content out, for example the private key of the user.

Affected products

  • Stashcat Heinekingmedia: up to and including 1.7.5

Published 2017-08-01. Last modified 2026-06-17.