A security flaw has been discovered in Modo Legend of the Phoenix up to 1.0.5. The affected element is an unknown function of the file AndroidManifest.xml of the component com.duige.hzw.multilingual. The manipulation results in improper export of android application components. The attack needs to be approached locally. The exploit has been released to the public and may be exploited. The vendor was contacted early about this disclosure but did not respond in any way.
References
Link | Resource |
---|---|
https://github.com/KMov-g/androidapps/blob/main/com.duige.hzw.multilingual.md | Exploit Third Party Advisory Mitigation |
https://github.com/KMov-g/androidapps/blob/main/com.duige.hzw.multilingual.md#steps-to-reproduce | Exploit Third Party Advisory Mitigation |
https://vuldb.com/?ctiid.321889 | Permissions Required VDB Entry |
https://vuldb.com/?id.321889 | Third Party Advisory VDB Entry |
https://vuldb.com/?submit.638078 | Third Party Advisory VDB Entry |
https://github.com/KMov-g/androidapps/blob/main/com.duige.hzw.multilingual.md | Exploit Third Party Advisory Mitigation |
https://github.com/KMov-g/androidapps/blob/main/com.duige.hzw.multilingual.md#steps-to-reproduce | Exploit Third Party Advisory Mitigation |
Configurations
Configuration 1 (hide)
AND |
|
History
08 Sep 2025, 16:07
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/KMov-g/androidapps/blob/main/com.duige.hzw.multilingual.md - Exploit, Third Party Advisory, Mitigation | |
References | () https://github.com/KMov-g/androidapps/blob/main/com.duige.hzw.multilingual.md#steps-to-reproduce - Exploit, Third Party Advisory, Mitigation | |
References | () https://vuldb.com/?ctiid.321889 - Permissions Required, VDB Entry | |
References | () https://vuldb.com/?id.321889 - Third Party Advisory, VDB Entry | |
References | () https://vuldb.com/?submit.638078 - Third Party Advisory, VDB Entry | |
First Time |
Modo
Modo legend Of The Phoenix Google android |
|
CWE | NVD-CWE-noinfo | |
CPE | cpe:2.3:o:google:android:*:*:*:*:*:*:*:* cpe:2.3:a:modo:legend_of_the_phoenix:*:*:*:*:*:android:*:* |
02 Sep 2025, 16:15
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/KMov-g/androidapps/blob/main/com.duige.hzw.multilingual.md - | |
References | () https://github.com/KMov-g/androidapps/blob/main/com.duige.hzw.multilingual.md#steps-to-reproduce - |
29 Aug 2025, 21:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-08-29 21:15
Updated : 2025-09-08 16:07
NVD link : CVE-2025-9677
Mitre link : CVE-2025-9677
CVE.ORG link : CVE-2025-9677
JSON object : View
Products Affected
- android
modo
- legend_of_the_phoenix
CWE