Communication Channel Vulnerability in VoiceTra by National Institute of Information and Communications Technology
CVE-2026-72506

5.1MEDIUM

What is CVE-2026-72506?

VoiceTra, developed by the National Institute of Information and Communications Technology, is vulnerable due to an incorrectly specified destination in a communication channel. This flaw can mislead users to a malicious server controlled by an attacker. Such redirection poses significant risks, including the potential theft of sensitive input data and delivery of misleading results to the users.

Affected Version(s)

"VoiceTra(Voice Translator)" for Android 9.1.3 <= 9.2.0

"VoiceTra(Voice Translator)" for iOS 9.1.3 <= 9.2.0

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

CVSS V3.0

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.