Telpo MDM 1.4.6 thru 1.4.9 for Android contains sensitive...
Critical severity
Unreviewed
Published
Aug 26, 2025
to the GitHub Advisory Database
•
Updated Aug 27, 2025
Description
Published by the National Vulnerability Database
Aug 26, 2025
Published to the GitHub Advisory Database
Aug 26, 2025
Last updated
Aug 27, 2025
Telpo MDM 1.4.6 thru 1.4.9 for Android contains sensitive administrator credentials and MQTT server connection details (IP/port) that are stored in plaintext within log files on the device's external storage. This allows attackers with access to these logs to: 1. Authenticate to the MDM web platform to execute administrative operations (device shutdown/factory reset/software installation); 2. Connect to the MQTT server to intercept/publish device data.
References