SirenGPS Android Application 2.19.44 is vulnerable to Incorrect Access Control. An authenticated attacker can manipulate user identifier parameters to bypass authorization controls and gain unauthorized READ and WRITE access to other users' personal information. The API fails to validate that the requesting user is authorized to access the target user's data.
History

Wed, 05 Aug 2026 23:45:00 +0000

Type Values Removed Values Added
Title Incorrect Access Control Allows Bypassing Authentication in SirenGPS Android App
Weaknesses CWE-284

Wed, 05 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
Description SirenGPS Android Application 2.19.44 is vulnerable to Incorrect Access Control. An authenticated attacker can manipulate user identifier parameters to bypass authorization controls and gain unauthorized READ and WRITE access to other users' personal information. The API fails to validate that the requesting user is authorized to access the target user's data.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-08-05T21:52:45.164Z

Reserved: 2025-10-27T00:00:00.000Z

Link: CVE-2025-63822

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T23:30:04Z