AG Life Logger Android App version v1.0.2.72 and before (package name com.donki.healthy), developed by IO FIT, K.K., contains improper access control vulnerabilities. Exposed credentials in traffic may allow attackers to misuse cloud resources, and predictable verification codes make brute-force account logins feasible. Successful exploitation could result in account compromise, privacy breaches, and abuse of cloud resources.
Metrics
Affected Vendors & Products
References
History
Fri, 31 Oct 2025 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Google
Google android Io Fit Io Fit ag Life Logger App |
|
| Vendors & Products |
Google
Google android Io Fit Io Fit ag Life Logger App |
Thu, 30 Oct 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-284 | |
| Metrics |
cvssV3_1
|
Thu, 30 Oct 2025 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | AG Life Logger Android App version v1.0.2.72 and before (package name com.donki.healthy), developed by IO FIT, K.K., contains improper access control vulnerabilities. Exposed credentials in traffic may allow attackers to misuse cloud resources, and predictable verification codes make brute-force account logins feasible. Successful exploitation could result in account compromise, privacy breaches, and abuse of cloud resources. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published: 2025-10-30T00:00:00.000Z
Updated: 2025-10-30T20:52:38.303Z
Reserved: 2025-09-26T00:00:00.000Z
Link: CVE-2025-61120
Updated: 2025-10-30T20:52:30.268Z
Status : Received
Published: 2025-10-30T17:15:39.233
Modified: 2025-10-30T21:15:36.170
Link: CVE-2025-61120
No data.
ReportizFlow