Path Traversal Vulnerability in Smartbit CommV Smartschool App
CVE-2025-14702

4.8MEDIUM

Key Information:

Vendor
CVE Published:
15 December 2025

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC

What is CVE-2025-14702?

A vulnerability exists in the Smartbit CommV Smartschool App, specifically within the component be.smartschool.mobile.SplashActivity. This flaw allows for path traversal through manipulation of certain inputs, potentially granting unauthorized access to critical system files and folders. The exploit requires local access to the device, and while the method has been publicized, the vendor did not respond to early notifications regarding this issue. Users of version 10.4.4 and earlier are advised to take appropriate action to secure their applications.

Affected Version(s)

Smartschool App 10.4.0

Smartschool App 10.4.1

Smartschool App 10.4.2

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

CVSS V4

Score:
4.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Lu1u (VulDB User)
.
CVE-2025-14702 : Path Traversal Vulnerability in Smartbit CommV Smartschool App