---
id: CVE-2020-25493
title: >-
  Oclean Mobile Application 2.1.2 communicates with an external website using
  HTTP so it is possible to eavesdrop the network traffic
summary: >-
  Oclean Mobile Application 2.1.2 communicates with an external website using
  HTTP so it is possible to eavesdrop the network traffic. The content of HTTP
  payload is encrypted using XOR with a hardcoded key, which allows for the
  possibilit…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-327
  - CWE-798
vendor: oclean
product: oclean
affected:
  - oclean = 2.1.2
published: '2021-02-11'
updated: '2026-07-05'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2020-25493'
references:
  - url: 'https://github.com/c3r34lk1ll3r/decrypt-oclean-traffic'
    label: cve@mitre.org
  - url: >-
      https://play.google.com/store/apps/details?id=com.yunding.noopsychebrushforeign
    label: cve@mitre.org
  - url: 'http://oclean.com'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://github.com/c3r34lk1ll3r/decrypt-oclean-traffic'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://play.google.com/store/apps/details?id=com.yunding.noopsychebrushforeign
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.00893
epssPercentile: 0.57781
ingestedAt: '2026-07-05T02:00:01.367Z'
---

## Overview

Oclean Mobile Application 2.1.2 communicates with an external website using HTTP so it is possible to eavesdrop the network traffic. The content of HTTP payload is encrypted using XOR with a hardcoded key, which allows for the possibility to decode the traffic.

## Affected

- `oclean = 2.1.2`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
