CVE-2025-46408: Critical severity AVTECH EagleEyes vulnerability
An issue was discovered in the methods push.lite.avtech.com.AvtechLib.GetHttpsResponse and push.lite.avtech.com.PushHttpService.getNewHttpClient in AVTECH EagleEyes 2.0.0. The methods set ALLOWALLHOSTNAMEVERIFIER, bypassing domain validation.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-46408?
CVE-2025-46408 has a critical severity due to its potential to bypass hostname verification, leading to man-in-the-middle attacks.
How do I fix CVE-2025-46408?
To fix CVE-2025-46408, ensure that ALLOW_ALL_HOSTNAME_VERIFIER is not used and implement proper domain validation in your application.
What software is affected by CVE-2025-46408?
CVE-2025-46408 affects AVTECH EagleEyes version 2.0.0 on Android.
What is the impact of CVE-2025-46408?
The impact of CVE-2025-46408 includes the risk of attackers intercepting data through insecure HTTPS connections.
When was CVE-2025-46408 disclosed?
CVE-2025-46408 was disclosed in 2025, highlighting a significant security issue in the AVTECH application.