Description
The Flock Safety Pisco com.flocksafety.android.pisco application 6.21.11 for Android (installed on Falcon and Sparrow License Plate Readers and Bravo Edge AI Compute Devices) has a cleartext Auth0 client secret in its codebase. Because application binaries can be trivially decompiled or inspected, attackers can recover this OAuth secret without special privileges. This secret is intended to remain confidential and should never be embedded directly in client-side software.
INFO
Published Date :
2025-10-02T00:00:00.000Z
Last Modified :
2025-10-02T19:46:27.571Z
Source :
mitre
AFFECTED PRODUCTS
The following products are affected by CVE-2025-59406 vulnerability.
No data.
REFERENCES
Here, you will find a curated list of external links that provide in-depth information to CVE-2025-59406.