An issue was discovered in the method push.lite.avtech.com.MySSLSocketFactoryNew.checkServerTrusted in AVTECH EagleEyes 2.0.0. The custom X509TrustManager used in checkServerTrusted only checks the certificate's expiration date, skipping proper TLS chain validation.
References
| Link | Resource |
|---|---|
| https://github.com/shinyColumn/CVE-2025-50944 | Exploit Third Party Advisory |
| https://shinycolumn.notion.site/eagleeyes-lite | Exploit Third Party Advisory |
Configurations
History
No history.
Information
Published : 2025-09-15 14:15
Updated : 2025-10-14 19:41
NVD link : CVE-2025-50944
Mitre link : CVE-2025-50944
CVE.ORG link : CVE-2025-50944
JSON object : View
Products Affected
avtech
- eagleeyes\(lite\)
CWE
CWE-295
Improper Certificate Validation
