Description
In the Payeer Android application 2.5.0, an improper access control vulnerability exists in the authentication flow for the PIN change feature. A local attacker with root access to the device can dynamically instrument the app to bypass the current PIN verification check and directly modify the authentication PIN. This allows unauthorized users to change PIN without knowing the original/current PIN.
INFO
Published Date :
2025-09-29T00:00:00.000Z
Last Modified :
2025-09-30T17:24:05.044Z
Source :
mitre
AFFECTED PRODUCTS
The following products are affected by CVE-2025-57197 vulnerability.
| Vendors | Products |
|---|---|
|
|
| Payeer |
|
REFERENCES
Here, you will find a curated list of external links that provide in-depth information to CVE-2025-57197.
CVSS Vulnerability Scoring System
Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact