VYPR
Unrated severityNVD Advisory· Published Jul 26, 2012· Updated Apr 29, 2026

CVE-2012-3887

CVE-2012-3887

Description

AirDroid before 1.0.7 beta uses a cleartext base64 format for data transfer that is documented as an "Encrypted Transmission" feature, which allows remote attackers to obtain sensitive information by sniffing the local wireless network, as demonstrated by the SMS message content sent to the sdctl/sms/send/single/ URI.

Affected products

7
  • Airdroid/Airdroid7 versions
    cpe:2.3:a:airdroid:airdroid:*:beta:*:*:*:*:*:*+ 6 more
    • cpe:2.3:a:airdroid:airdroid:*:beta:*:*:*:*:*:*range: <=1.0.6
    • cpe:2.3:a:airdroid:airdroid:1.0.1:*:*:*:*:*:*:*
    • cpe:2.3:a:airdroid:airdroid:1.0.2:*:*:*:*:*:*:*
    • cpe:2.3:a:airdroid:airdroid:1.0.3:*:*:*:*:*:*:*
    • cpe:2.3:a:airdroid:airdroid:1.0.4:*:*:*:*:*:*:*
    • cpe:2.3:a:airdroid:airdroid:1.0.4:beta:*:*:*:*:*:*
    • cpe:2.3:a:airdroid:airdroid:1.0.5:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.