Path Traversal Vulnerability in Smartbit CommV Smartschool App
CVE-2025-14702
Key Information:
- Vendor
Smartbit Commv
- Status
- Vendor
- CVE Published:
- 15 December 2025
Badges
What is CVE-2025-14702?
A vulnerability exists in the Smartbit CommV Smartschool App, specifically within the component be.smartschool.mobile.SplashActivity. This flaw allows for path traversal through manipulation of certain inputs, potentially granting unauthorized access to critical system files and folders. The exploit requires local access to the device, and while the method has been publicized, the vendor did not respond to early notifications regarding this issue. Users of version 10.4.4 and earlier are advised to take appropriate action to secure their applications.
Affected Version(s)
Smartschool App 10.4.0
Smartschool App 10.4.1
Smartschool App 10.4.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
