Medium severity5.9NVD Advisory· Published Feb 17, 2021· Updated Jun 17, 2026
CVE-2020-25605
CVE-2020-25605
Description
Cleartext transmission of sensitive information in Agora Video SDK prior to 3.1 allows a remote attacker to obtain access to audio and video of any ongoing Agora video call through observation of cleartext network traffic.
Affected products
3- cpe:2.3:a:agora:video_software_development_kit:*:*:*:*:*:*:*:*Range: <3.1
- Agora/Video SDKdescription
Patches
Vulnerability mechanics
References
2- www.mcafee.com/blogs/other-blogs/mcafee-labs/dont-call-us-well-call-you-mcafee-atr-finds-vulnerability-in-agora-video-sdk/nvdExploitThird Party Advisory
- docs.agora.io/en/Agora%20Platform/downloadsnvdVendor Advisory
News mentions
0No linked articles in our index yet.