CVE-2025-20060: Dario Health Dario Application Database And Internet-Based Server Infrastructure

High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.

An attacker could expose cross-user personal identifiable information (PII) and personal health information transmitted to the Android device via the Dario Health application database.

Affected products

  • Dario Health Dario Application Database And Internet-Based Server Infrastructure: any version
  • Dario Health USB-C Blood Glucose Monitoring System Starter Kit Android Applications: before 5.8.7.0.36 (fixed in 5.8.7.0.36)

Published 2025-02-28. Last modified 2026-06-17.