Junglewise Threat Intelligence

CVE-2025-57197: Payeer Android application improper access control in PIN change feature

CVE-2025-57197 · Severity: medium · CVSS 6 · Published 2025-09-29

Executive brief

The Payeer Android application, a digital wallet used for managing and exchanging currency, contains a security flaw in its PIN change process. An attacker with physical access to a rooted device can bypass the requirement to know the current PIN when setting a new one. This could allow an unauthorized individual to gain full control over the wallet's security settings and potentially access funds if they have already compromised the device's administrative controls.

Technical details

An improper access control vulnerability (CWE-284) exists in the PIN change authentication flow of the Payeer Android app version 2.5.0. The vulnerability allows a local attacker with administrative (root) privileges to use dynamic instrumentation tools to bypass the logic responsible for verifying the existing PIN. By hooking the relevant methods, an attacker can force the application to accept a new PIN without providing the original credential. This bypass facilitates unauthorized modification of the authentication PIN, leading to a complete compromise of the application's local access security.

Affected products

  • Payeer Payeer Android application 2.5.0

Timeline

  • 2025-09-29: advisory: NVD published date

References