CVE-2019-13096: Tronlink Wallet

Critical severity, CVSS 9.8. EPSS: 1.1% chance of exploitation in the next 30 days.

TronLink Wallet 2.2.0 stores user wallet keystore in plaintext and places them in insecure storage. An attacker can read and reuse the user keystore of a valid user via /data/data/com.tronlink.wallet/shared_prefs/<wallet-name>.xml to gain unauthorized access.

Affected products

Published 2019-07-22. Last modified 2026-06-17.