---
id: CVE-2025-11645
title: >-
  A security vulnerability has been detected in Tomofun Furbo Mobile App up to
  7.57.0a on Android
summary: >-
  A security vulnerability has been detected in Tomofun Furbo Mobile App up to
  7.57.0a on Android. This affects an unknown part of the component
  Authentication Token Handler. The manipulation leads to insecure storage of
  sensitive informat…
severity: low
cvss: 2.4
cvssVector: 'CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-200
  - CWE-922
published: '2025-10-12'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T12:10:00.217'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-11645'
references:
  - url: 'https://github.com/dead1nfluence/Furbo-Advisories/blob/main/Insecure.md'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?ctiid.328056'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?id.328056'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?submit.661899'
    label: cna@vuldb.com
  - url: 'https://github.com/dead1nfluence/Furbo-Advisories/blob/main/Insecure.md'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
epss: 0.00196
epssPercentile: 0.08541
ingestedAt: '2026-10-08T12:39:48.697Z'
---

## Overview

A security vulnerability has been detected in Tomofun Furbo Mobile App up to 7.57.0a on Android. This affects an unknown part of the component Authentication Token Handler. The manipulation leads to insecure storage of sensitive information. It is possible to launch the attack on the physical device. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
