Vulnerabilities
Vulnerable Software
Ushareit:  >> Shareit  >> 4.0.34  Security Vulnerabilities
The SHAREit application before 4.0.42 for Android allows a remote attacker (on the same network or joining public "open" Wi-Fi hotspots created by the application when file transfer is initiated) to download arbitrary files from the device including contacts, photos, videos, sound clips, etc. The attacker must be authenticated as a "recognized device."
CVSS Score
5.3
EPSS Score
0.002
Published
2019-03-22
The SHAREit application before 4.0.36 for Android allows a remote attacker (on the same network or joining public "open" Wi-Fi hotspots created by the application when file transfer is initiated) to bypass authentication by trying to fetch a non-existing page. When the non-existing page is requested, the application responds with a 200 status code and empty page, and adds the requesting client device into the list of recognized devices.
CVSS Score
8.8
EPSS Score
0.003
Published
2019-03-22


Contact Us

Shodan ® - All rights reserved