---
id: CVE-2021-36460
title: >-
  VeryFitPro (com.veryfit2hr.second) 3.2.8 hashes the account's password locally
  on the device and uses the hash to authenticate in all communication with the
  backend API, including login, registration and changing of passwords
summary: >-
  VeryFitPro (com.veryfit2hr.second) 3.2.8 hashes the account's password locally
  on the device and uses the hash to authenticate in all communication with the
  backend API, including login, registration and changing of passwords. This
  allow…
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-287
vendor: veryfitpro_project
product: veryfitpro
affected:
  - veryfitpro <= 3.3.7
published: '2022-04-25'
updated: '2026-07-05'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2021-36460'
references:
  - url: 'http://www.i-doo.cn'
    label: cve@mitre.org
  - url: 'https://github.com/martinfrancois/CVE-2021-36460'
    label: cve@mitre.org
  - url: 'http://veryfitpro.com'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.i-doo.cn'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://github.com/martinfrancois/CVE-2021-36460'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
  - exploit-available
epss: 0.00365
epssPercentile: 0.27665
ingestedAt: '2026-07-06T17:03:24.165Z'
exploits:
  github: 1
  githubRepos:
    - 'https://github.com/martinfrancois/CVE-2021-36460'
  checkedAt: '2026-09-26T09:05:27.662Z'
exploitAvailable: true
---

## Overview

VeryFitPro (com.veryfit2hr.second) 3.2.8 hashes the account's password locally on the device and uses the hash to authenticate in all communication with the backend API, including login, registration and changing of passwords. This allows an attacker in possession of a hash to takeover a user's account, rendering the benefits of storing hashed passwords in the database useless.

## Affected

- `veryfitpro <= 3.3.7`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
