High severity8.1NVD Advisory· Published Jun 16, 2021· Updated Jun 17, 2026
CVE-2021-32612
CVE-2021-32612
Description
The VeryFitPro (com.veryfit2hr.second) application 3.2.8 for Android does all communication with the backend API over cleartext HTTP. This includes logins, registrations, and password change requests. This allows information theft and account takeover via network sniffing.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:i-doo:veryfitpro:3.2.8:*:*:*:*:android:*:*
- VeryFitPro/VeryFitProdescription
- Range: =3.2.8
Patches
Vulnerability mechanics
References
4- seclists.org/fulldisclosure/2021/Jun/45nvdExploitMailing ListThird Party Advisory
- trovent.github.io/security-advisories/TRSA-2105-01/TRSA-2105-01.txtnvdExploitThird Party Advisory
- trovent.io/security-advisory-2105-01nvdExploitThird Party Advisory
- play.google.com/store/apps/detailsnvdProduct
News mentions
0No linked articles in our index yet.