CVE-2025-46408 is an improper certificate validation issue in AVTECH EagleEyes 2.0.0. The vulnerability is present in the methods push.lite.avtech.com.AvtechLib.GetHttpsResponse and push.lite.avtech.com.Push_HttpService.getNewHttpClient, which configure ALLOW_ALL_HOSTNAME_VERIFIER for HTTPS connections. As a result, the application does not properly validate that the server certificate hostname matches the intended remote host, effectively bypassing domain validation during TLS sessions.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository provides a proof-of-concept (PoC) exploit for CVE-2025-46408, a critical vulnerability in the EagleEyes Lite Android application (version 2.0.0) by AVTECH. The vulnerability arises from improper hostname verification in HTTPS connections, allowing attackers to perform man-in-the-middle (MITM) attacks by presenting any certificate, including self-signed ones. The repository contains two files: a detailed README.md explaining the vulnerability, affected code, and exploitation scenario, and a Frida script (hook.js) that forcibly sets the SDK_API_26 flag to false (emulating a pre-Android 8.0 environment) and hooks the vulnerable GetHttpsResponse methods. The Frida script logs calls to these methods, confirming that the application is using the insecure logic. The exploit demonstrates that an attacker on the same network can intercept or modify sensitive communications between the app and AVTECH backend services. No hardcoded network endpoints or IPs are present in the code, but the exploit targets the app's internal Java class and methods responsible for HTTPS communication.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
3 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.