Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2025-20615

The Qardio Arm iOS application exposes sensitive data such as usernames and passwords in a plist file. This allows an attacker to log in to production-level development accounts and access an engineering backdoor in the application. The engineering backdoor allows the attacker to send hex-based commands over a UI-based terminal.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 5.1%
CVSS Severity
CVSS v3 Score 6.2
Products affected by CVE-2025-20615
  • Qardio » Qardio » Version: 2.7.4
    cpe:2.3:a:qardio:qardio:2.7.4


Contact Us

Shodan ® - All rights reserved