CVE-2025-56608: Medium severity Sourcecodester Coronavirus Tracker App India vulnerability

Published Sep 3, 2025
·
Updated

The SourceCodester Android application "Corona Virus Tracker App India" 1.0 uses MD5 for digest authentication in OkHttpClientWrapper.java. The handleDigest() function employs MessageDigest.getInstance("MD5") to hash credentials. MD5 is a broken cryptographic algorithm known to allow hash collisions. This makes the authentication mechanism vulnerable to replay, spoofing, or brute-force attacks, potentially leading to unauthorized access. The vulnerability corresponds to CWE-327 and aligns with OWASP M5: Insufficient Cryptography and MASVS MSTG-CRYPTO-4.

Affected Software

2 affected components
Sourcecodester Coronavirus Tracker App India=1.0
Donbermoy Android Corona Virus Tracker App For India=1.0

Event History

Sep 3, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-56608?

CVE-2025-56608 has a medium severity due to the use of MD5 for digest authentication which is vulnerable to hash collision attacks.

2

How do I fix CVE-2025-56608?

To fix CVE-2025-56608, replace the MD5 hashing algorithm with a more secure algorithm such as SHA-256 in the authentication process.

3

What vulnerabilities does CVE-2025-56608 introduce?

CVE-2025-56608 introduces risks of credential compromise and unauthorized access due to the weak MD5 algorithm.

4

Which version of the application is affected by CVE-2025-56608?

CVE-2025-56608 affects version 1.0 of the Corona Virus Tracker App India application.

5

Is CVE-2025-56608 a widespread vulnerability?

CVE-2025-56608 may not be widespread but poses a significant risk to users of the affected application if not addressed.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203