CVE-2024-39886: Dream Train Internet Inc Tone Store App
Low severity, CVSS 3.7. EPSS: 0.3% chance of exploitation in the next 30 days.
TONE store App version 3.4.2 and earlier contains an issue with unprotected primary channel. Since TONE store App communicates with TONE store website in cleartext, a man-in-the-middle attack may allow an attacker to obtain and/or alter communications of the affected App.
Affected products
- Dream Train Internet Inc Tone Store App: up to and including 3.4.2
Published 2024-07-10. Last modified 2026-06-17.