Medium SEVERITY — Vulnerability

OTP Disclosure via Exported TokenContentProvider

CVSSv3 Score: 5.0 An improper export of Android application components [CWE-926] in FortiTokenAndroid may allow other applications on the device to read the OTP code via an exported Content Provider URI. Revised on 2026-05-12 00:00:00

Platform
FortiGate / FortiOS
CVSS Score
5.0/10
Advisory
FG-IR-26-130
Published
12 May 2026
Views
3
Primary source: Review the official advisory at fortiguard.fortinet.com Kaynağa Git

Summary

CVSSv3 Score: 5.0 An improper export of Android application components [CWE-926] in FortiTokenAndroid may allow other applications on the device to read the OTP code via an exported Content Provider URI. Revised on 2026-05-12 00:00:00

Source

This entry was automatically ingested; verify the content before publishing.

FortiGate / FortiOS — Related Advisories

VIEW ALL →