CVE-2014-6909
Description
The Coca-Cola FM Peru (aka com.enyetech.radio.coca_cola.fm_pe) application 2.0.41716 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Coca-Cola FM Peru for Android fails to validate SSL certificates, enabling man-in-the-middle attacks to intercept sensitive data.
Vulnerability
The Coca-Cola FM Peru application (com.enyetech.radio.coca_cola.fm_pe) version 2.0.41716 for Android does not properly verify X.509 certificates from SSL servers. This flaw was identified through dynamic SSL validation testing as part of a broader study of Android applications [1][2]. The application fails to validate the certificate chain, making HTTPS connections vulnerable to interception.
Exploitation
An attacker with network access (e.g., on the same Wi-Fi network) can perform a man-in-the-middle attack by presenting a crafted certificate. The application will accept the fraudulent certificate without proper validation, allowing the attacker to intercept and potentially modify traffic between the app and its servers.
Impact
Successful exploitation allows the attacker to view or modify network traffic that should have been protected by HTTPS. This could lead to disclosure of sensitive information such as login credentials or personal data, and in some cases, arbitrary code execution depending on the app's functionality [1].
Mitigation
The vendor has not released a patched version as of the publication date. Users are advised to avoid using the application and instead access Coca-Cola FM Peru content via a web browser, which typically provides proper SSL validation [1]. The app is listed in the CERT/CC tracking spreadsheet of vulnerable applications [2].
AI Insight generated on May 23, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2cpe:2.3:a:enyetech:coca-cola_fm_peru:2.0.41716:*:*:*:*:android:*:*+ 1 more
- cpe:2.3:a:enyetech:coca-cola_fm_peru:2.0.41716:*:*:*:*:android:*:*
- (no CPE)range: = 2.0.41716
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- www.kb.cert.org/vuls/id/569297nvdUS Government Resource
- www.kb.cert.org/vuls/id/582497nvdUS Government Resource
- docs.google.com/spreadsheets/d/1t5GXwjw82SyunALVJb2w0zi3FoLRIkfGPc7AMjRF0r4/editnvd
News mentions
0No linked articles in our index yet.