---
id: CVE-2025-63823
title: >-
  My Safetipin Android Application 5.2.1 contains Hardcoded credentials in the
  authentication module, which allows remote attackers to bypass authentication
  and gain unauthorized access to user accounts via predictable OTP values.
summary: >-
  My Safetipin Android Application 5.2.1 contains Hardcoded credentials in the
  authentication module, which allows remote attackers to bypass authentication
  and gain unauthorized access to user accounts via predictable OTP values.
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-798
published: '2026-08-05'
updated: '2026-09-09'
sourceUpdated: '2026-09-09T16:04:24.933'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-63823'
references:
  - url: >-
      https://github.com/Leoccc98/cve-reports/blob/main/advisories/CVE-2025-63823/README.md
    label: cve@mitre.org
  - url: 'https://play.google.com/store/apps/details?id=com.safetipin.mysafetipin'
    label: cve@mitre.org
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: total
  timestamp: '2026-08-06T14:05:16.867218Z'
ingestedAt: '2026-09-14T13:49:58.775Z'
epss: 0.00813
epssPercentile: 0.55186
---

## Overview

My Safetipin Android Application 5.2.1 contains Hardcoded credentials in the authentication module, which allows remote attackers to bypass authentication and gain unauthorized access to user accounts via predictable OTP values.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
