CVE-2025-68713
Last modified
CVE-2025-68713 is a high-severity vulnerability rated 8/10 on the CVSS scale. An issue was discovered in Rakuten Send Anywhere (File Transfer) for Android (com.estmob.android.sendanywhere) 23.2.9. The vulnerability allows untrusted applications (with no permissions) to force arbitrary file downloads into the app's scoped storage. EPSS estimates a 0.28% chance of exploitation in the next 30 days.
Description
An issue was discovered in Rakuten Send Anywhere (File Transfer) for Android (com.estmob.android.sendanywhere) 23.2.9. The vulnerability allows untrusted applications (with no permissions) to force arbitrary file downloads into the app's scoped storage. The resulting files appear in the application's trusted Received interface. These conditions establish a vector for arbitrary code execution if the payload is an APK file, or a denial-of-service condition through resource exhaustion from oversized transfers.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-68713?
How severe is CVE-2025-68713?
How do I fix CVE-2025-68713?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-68708SailingLab AppLock (aka com.alpha.applock) 4.3.8 for Android…2.4
- CVE-2025-68709SailingLab AppLock (aka com.alpha.applock) 4.3.8 for Android…5.2
- CVE-2025-6871A vulnerability classified as critical has been found in Sou…9.8
- CVE-2025-68710Easyelife App lock (aka Fingerprint,Applock or locker.app.sa…2.4
- CVE-2025-68711AppLockZ App Lock and Fingerprint Lock (applock.passwordfing…2.4
- CVE-2025-68712SpSoft AppLock (com.sp.protector.free) 7.9.40 for Android al…5.5
- CVE-2025-68715An issue was discovered in Panda Wireless PWRU0 devices with…9.1
- CVE-2025-68716KAYSUS KS-WR3600 routers with firmware 1.0.5.9.1 enable the …8.4
- CVE-2025-68717KAYSUS KS-WR3600 routers with firmware 1.0.5.9.1 allow authe…9.4
- CVE-2025-68718KAYSUS KS-WR1200 routers with firmware 107 expose SSH and TE…5.4
- CVE-2025-68719KAYSUS KS-WR3600 routers with firmware 1.0.5.9.1 mishandle c…8.8
- CVE-2025-6872A vulnerability classified as critical was found in SourceCo…7.2
Are you affected by CVE-2025-68713?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
