CVE-2025-59406
The Flock Safety Pisco com.flocksafety.android.pisco application 6.21.11 for Android (installed on Falcon and Sparrow License Plate Readers and Bravo Edge AI Compute Devices) has a cleartext Auth0 client secret in its codebase. Because application binaries can be trivially decompiled or inspected, attackers can recover this OAuth secret without special privileges. This secret is intended to remain confidential and should never be embedded directly in client-side software.
Published:Oct 2, 2025
Last Modified:Oct 24, 2025
EPS:Oct 2, 2025
EPSS Score:0.00007
CVSS Score:6.2
Affected Products
Vendor
Product
Action
Vendor
Flock Safety
Product
Bravo Edge Ai Compute Device
Flock Safety
Bravo Edge Ai Compute Device
Vendor
Flocksafety
Product
Bravo Edge Ai Compute Device
Flocksafety
Bravo Edge Ai Compute Device
Vendor
Flocksafety
Product
Falcon
Flocksafety
Falcon
Vendor
Flocksafety
Product
Flock Safety
Flocksafety
Flock Safety
Vendor
Flocksafety
Product
License Plate Reader
Flocksafety
License Plate Reader
Vendor
Flocksafety
Product
Pisco
Flocksafety
Pisco
Vendor
Google
Product
Android
Google
Android
Exploits
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
