CVE-2025-63435: Xtooltech Xtool Anyscan
Medium severity, CVSS 4.3. EPSS: 0.4% chance of exploitation in the next 30 days.
Xtooltech Xtool AnyScan Android Application 4.40.40 is Missing Authentication for Critical Function. The server-side endpoint responsible for serving update packages for the application does not require any authentication. This allows an unauthenticated remote attacker to freely download official update packages..
Affected products
- Xtooltech Xtool Anyscan: up to and including 4.40.40
Published 2025-11-24. Last modified 2026-06-17.