---
id: CVE-2025-63822
title: SirenGPS Android Application 2.19.44 is vulnerable to Incorrect Access Control
summary: >-
  SirenGPS Android Application 2.19.44 is vulnerable to Incorrect Access
  Control. An authenticated attacker can manipulate user identifier parameters
  to bypass authorization controls and gain unauthorized READ and WRITE access
  to other use…
severity: high
cvss: 8.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'
cwe:
  - CWE-284
published: '2026-08-05'
updated: '2026-09-09'
sourceUpdated: '2026-09-09T16:04:24.933'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-63822'
references:
  - url: >-
      https://github.com/Leoccc98/cve-reports/blob/main/advisories/CVE-2025-63822/README.md
    label: cve@mitre.org
  - url: 'https://play.google.com/store/apps/details?id=com.sirengps.mobile'
    label: cve@mitre.org
tags:
  - nvd
epss: 0.00386
epssPercentile: 0.29915
ingestedAt: '2026-09-09T16:14:05.512Z'
---

## Overview

SirenGPS Android Application 2.19.44 is vulnerable to Incorrect Access Control. An authenticated attacker can manipulate user identifier parameters to bypass authorization controls and gain unauthorized READ and WRITE access to other users' personal information. The API fails to validate that the requesting user is authorized to access the target user's data.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
