CVE-2025-9135

5.3 MEDIUM
Published: August 19, 2025 Modified: April 29, 2026
View on NVD

Description

A vulnerability was detected in Verkehrsauskunft ร–sterreich SmartRide, cleVVVer, BusBahnBim and Salzburg Verkehr up to 12.1.1(258) on Android. The impacted element is an unknown function of the file AndroidManifest.xml. The manipulation results in improper export of android application components. The attack must be initiated from a local position. The exploit is now public and may be used. Upgrading to version 12.1.2(259) is sufficient to resolve this issue. Upgrading the affected component is recommended. The vendor was contacted early and fixed the issue by "[r]emoving the task affinity of the app so it can't be copied".

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

CVSS v3.x Details

0.0 Low Medium High Critical 10.0
Vector String
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
https://github.com/KMov-g/androidapps/blob/main/de.hafas.android.vvt.md
Source: cna@vuldb.com
Exploit Third Party Advisory
https://vuldb.com/?ctiid.320515
Source: cna@vuldb.com
Permissions Required VDB Entry
https://vuldb.com/?id.320515
Source: cna@vuldb.com
Third Party Advisory VDB Entry
https://vuldb.com/?submit.615276
Source: cna@vuldb.com
Third Party Advisory VDB Entry
https://vuldb.com/?submit.615278
Source: cna@vuldb.com
Third Party Advisory VDB Entry
https://vuldb.com/?submit.628235
Source: cna@vuldb.com
Third Party Advisory VDB Entry
https://github.com/KMov-g/androidapps/blob/main/de.hafas.android.vvt.md
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
Exploit Third Party Advisory
https://github.com/KMov-g/androidapps/blob/main/de.hafas.android.vvt.md#steps-to-reproduce
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
Exploit Third Party Advisory

9 reference(s) from NVD

Quick Stats

CVSS v3 Score
5.3 / 10.0
EPSS (Exploit Probability)
0.0%
6th percentile
Exploitation Status
Not in CISA KEV

Weaknesses (CWE)

Affected Vendors

verkehrsauskunft