CVE-2025-27839
operations/attestation/AttestationTask.kt in the Tangem SDK before 5.18.3 for Android has a logic flow in offline wallet attestation (genuineness check) that causes verification results to be disregarded during the first scan of a card. Exploitation may not have been possible.
Scoring
- Severity
- LOW
- CVSS base score
- 3.2
- CVSS vector
- CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N
- EPSS probability
- 0.35%
- CWE
- CWE-1025
- Published
- 2025-03-07
- Last modified
- 2026-03-13
Affected products
- Tangem SDK
Weakness type
Related vulnerabilities
- CVE-2023-54390 — PocketMine-MP before 5.3.1 Denial of Service via LoginPacket
- CVE-2026-78619 — Punk::Plugin::TOTP versions before 0.05 for Perl accept another account's recovery code at the two-factor challenge because totp_use_recovery compares user identifiers numerically
- CVE-2026-75840 — ArcadeDB before 26.8.1 Arbitrary File Read via Unescaped Regex
- CVE-2025-71377 — stoatchat before 20250210-1 Unrestricted Message History Fetch
- CVE-2026-9800 — Keycloak-policy-enforcer: keycloak policy enforcer: authorization bypass via incorrect uri comparison
- CVE-2026-48860 — Distribution-over-TLS LAN allowlist silently bypassed due to sockname/peername confusion in inet_tls_dist
- CVE-2026-40880 — Zebra: Cached Mempool Verification Bypasses Consensus Rules for Ahead-of-Tip Blocks
- CVE-2026-40227 — In systemd 260 before 261, a local unprivileged user can trigger an assert via an IPC API call with...