VYPR
Unrated severityNVD Advisory· Published Oct 4, 2014· Updated May 6, 2026

CVE-2014-6909

CVE-2014-6909

Description

The Coca-Cola FM Peru (aka com.enyetech.radio.coca_cola.fm_pe) application 2.0.41716 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Coca-Cola FM Peru for Android fails to validate SSL certificates, enabling man-in-the-middle attacks to intercept sensitive data.

Vulnerability

The Coca-Cola FM Peru application (com.enyetech.radio.coca_cola.fm_pe) version 2.0.41716 for Android does not properly verify X.509 certificates from SSL servers. This flaw was identified through dynamic SSL validation testing as part of a broader study of Android applications [1][2]. The application fails to validate the certificate chain, making HTTPS connections vulnerable to interception.

Exploitation

An attacker with network access (e.g., on the same Wi-Fi network) can perform a man-in-the-middle attack by presenting a crafted certificate. The application will accept the fraudulent certificate without proper validation, allowing the attacker to intercept and potentially modify traffic between the app and its servers.

Impact

Successful exploitation allows the attacker to view or modify network traffic that should have been protected by HTTPS. This could lead to disclosure of sensitive information such as login credentials or personal data, and in some cases, arbitrary code execution depending on the app's functionality [1].

Mitigation

The vendor has not released a patched version as of the publication date. Users are advised to avoid using the application and instead access Coca-Cola FM Peru content via a web browser, which typically provides proper SSL validation [1]. The app is listed in the CERT/CC tracking spreadsheet of vulnerable applications [2].

AI Insight generated on May 23, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • cpe:2.3:a:enyetech:coca-cola_fm_peru:2.0.41716:*:*:*:*:android:*:*+ 1 more
    • cpe:2.3:a:enyetech:coca-cola_fm_peru:2.0.41716:*:*:*:*:android:*:*
    • (no CPE)range: = 2.0.41716

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.