Junglewise Threat Intelligence

CVE-2026-41281: KDDI Anshin Filter for au cleartext transmission of sensitive information

CVE-2026-41281 · Severity: medium · CVSS 4.8 · Published 2026-05-14

Executive brief

The Anshin Filter for au Android application, a parental control and web filtering tool, fails to encrypt sensitive data during transmission. This allows an attacker positioned on the same network, such as a public Wi-Fi hotspot, to intercept or modify the app's communications. This could lead to the exposure of private user information or the tampering of filtering settings.

Technical details

The Android application 'Anshin Filter for au' (versions prior to 4.9_b0003) is vulnerable to CWE-319 (Cleartext Transmission of Sensitive Information). The application fails to use encrypted protocols (like HTTPS) for certain sensitive communications, making it susceptible to Man-in-the-Middle (MitM) attacks. An unauthenticated attacker on the network path can capture plaintext traffic to disclose sensitive data or inject/modify data to tamper with the application's functionality. The vulnerability is addressed in version 4.9_b0003.

Affected products

  • KDDI CORPORATION Anshin Filter for au (あんしんフィルター for au) prior to 4.9_b0003

Timeline

  • 2026-05-13: advisory: JVN advisory published by JPCERT/CC
  • 2026-05-14: disclosed: CVE published to NVD dataset

References