CVE-2025-7890 Details
Description
A vulnerability was found in Dunamu StockPlus App up to 7.62.10 on Android. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file AndroidManifest.xml of the component com.dunamu.stockplus. The manipulation leads to improper export of android application components. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability allowing task hijacking has been identified in the Dunamu StockPlus App for Android, in versions through 7.62.10. This issue arises from an improper export of application components, specifically within the AndroidManifest.xml file of the com.dunamu.stockplus component. The vulnerability allows malicious apps to inherit permissions from vulnerable apps, potentially leading to phishing attacks by manipulating or taking over tasks on the device.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 21, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/KMov-g/androidapps/blob/main/com.dunamu.stockplus.md | CISA-ADP | ExploitMitigationThird Party Advisory |
| https://github.com/KMov-g/androidapps/blob/main/com.dunamu.stockplus.md#steps-to-reproduce | CISA-ADP | ExploitMitigationThird Party Advisory |
| https://github.com/KMov-g/androidapps/blob/main/com.dunamu.stockplus.md | [email protected] | ExploitMitigationThird Party Advisory |
| https://github.com/KMov-g/androidapps/blob/main/com.dunamu.stockplus.md#steps-to-reproduce | [email protected] | ExploitMitigationThird Party Advisory |
| https://vuldb.com/?ctiid.317005 | [email protected] | Permissions RequiredVDB Entry |
| https://vuldb.com/?id.317005 | [email protected] | Third Party AdvisoryVDB Entry |
| https://vuldb.com/?submit.615270 | [email protected] | Third Party AdvisoryVDB Entry |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
| CWE-926 | Improper Export of Android Application Components | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| dunamu stockplus | <= 7.62.10 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 29, 2026 | Data Remediation | [email protected] |
| Sep 17, 2025 | Initial Analysis | [email protected] |
| Jul 21, 2025 | CVE Modified | CISA-ADP |
| Jul 20, 2025 | New CVE Received | [email protected] |