The Xelex MobileTrack application 2.3.7 and earlier for Android uses hardcoded credentials, which allows remote attackers to obtain sensitive information via an unencrypted (1) FTP or (2) HTTP session.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Mobiletrack | Xelex | * | 2.3.7 (including) |