The method push.lite.avtech.com.AvtechLib.GetHttpsResponse in AVTECH EagleEyes Lite 2.0.0 transmits sensitive information, including internal server URLs, account IDs, passwords, and device tokens, as plaintext query parameters over HTTPS. Although the transmission occurs over HTTPS, the use of query parameters exposes sensitive data in browser history, server logs, and potentially to intermediaries if HTTPS is improperly configured.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository demonstrates a proof-of-concept (PoC) exploit for CVE-2025-50110, a vulnerability in the EagleEyes Lite Android application (version 2.0.0 by AVTECH). The vulnerability is due to the application's practice of transmitting sensitive information (such as account IDs and passwords) in cleartext within the URL query string of HTTPS requests, specifically in the GetHttpsResponse() method. The repository contains two files: a detailed README.md explaining the vulnerability, affected versions, and exploitation scenario, and a Frida hook script (hook.js). The hook.js script is written in JavaScript for use with Frida and hooks the AvtechLib.GetHttpsResponse() method to log the URLs and responses, thereby exposing any sensitive data transmitted. The exploit requires local access to the device (or emulator) to inject the Frida script, and is primarily a PoC for demonstrating the vulnerability rather than a weaponized exploit. No hardcoded network endpoints are present, but the script targets the AvtechLib Java class and its methods within the EagleEyes Lite app.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.