Description

In the Payeer Android application 2.5.0, an improper access control vulnerability exists in the authentication flow for the PIN change feature. A local attacker with root access to the device can dynamically instrument the app to bypass the current PIN verification check and directly modify the authentication PIN. This allows unauthorized users to change PIN without knowing the original/current PIN.

INFO

Published Date :

2025-09-29T00:00:00.000Z

Last Modified :

2025-09-30T17:24:05.044Z

Source :

mitre
AFFECTED PRODUCTS

The following products are affected by CVE-2025-57197 vulnerability.

Vendors Products
Google
  • Android
Payeer
  • Payeer App

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact