Improper Export Vulnerability in Modo Legend of the Phoenix by Duige
CVE-2025-9677
Key Information:
- Vendor
Modo
- Status
- Vendor
- CVE Published:
- 29 August 2025
Badges
What is CVE-2025-9677?
A security flaw has been identified in the Modo Legend of the Phoenix app, specifically in an unknown function within the AndroidManifest.xml file of the com.duige.hzw.multilingual component. This flaw leads to the improper export of Android application components, potentially enabling local attacks. The exploit is publicly available, and attempts to contact the vendor regarding this security issue were met with no response.
Affected Version(s)
Legend of the Phoenix 1.0.0
Legend of the Phoenix 1.0.1
Legend of the Phoenix 1.0.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved