CVE-2025-15509

Severity CVSS v4.0:
HIGH
Type:
CWE-306 Missing Authentication for Critical Function
Publication date:
27/02/2026
Last modified:
09/03/2026

Description

The SmartRemote module has insufficient restrictions on loading URLs, which may lead to some information leakage.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:vivo:smartremote_module:*:*:*:*:*:android:*:* 5.1.2.0 (excluding)


References to Advisories, Solutions, and Tools