CVE-2025-63289 Details
Description
Sogexia Android App Compile Affected SDK v35, Max SDK 32 and fixed in v36, was discovered to contain hardcoded encryption keys in the encryption_helper.dart file
A vulnerability exists in the Sogexia Android application, specifically in versions compiled with SDK 35 and prior to 36. The issue involves hardcoded encryption keys embedded in the 'encryption_helper.dart' file. This vulnerability was identified through static analysis and reverse engineering of the app's APK, revealing Base64-encoded cryptographic material, including sequences resembling AES keys, directly embedded in the code.
Users of the Sogexia Android app should update to version 36 or later, where this vulnerability has been addressed by removing hardcoded keys and likely implementing a secure key management process.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Nov 13, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://medium.com/@sudosu01/information-disclosure-hardcoded-encryption-keys-fc375abf68a3 | [email protected] | Third Party Advisory |
| https://www.linkedin.com/in/umanhonlengabriel | [email protected] | Not Applicable |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-321 | Use of Hard-coded Cryptographic Key | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| sogexia sogexia | 35 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jan 5, 2026 | Initial Analysis | [email protected] |
| Nov 13, 2025 | CVE Modified | CISA-ADP |
| Nov 12, 2025 | New CVE Received | [email protected] |