Published:2025/07/22  Last Updated:2025/07/22

JVN#07825095
"region PAY" App for Android vulnerable to insertion of sensitive information into log file

Overview

"region PAY" App for Android provided by Gift Pad Co.,Ltd. is vulnerable to insertion of sensitive information into log file.

Products Affected

  • "region PAY" App for Android prior to 1.5.28

Description

"region PAY" App for Android provided by Gift Pad Co.,Ltd. contains the following vulnerability.

  • Insertion of sensitive information into log file (CWE-532)
    • CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N Base Score 2.4
    • CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N Base Score 2.4
    • CVE-2025-52580

Impact

Sensitive user information may be exposed to an attacker who has access to the application logs.

Solution

Update the Application
Update the application to the latest version according to the information provided by the developer.
The developer has released the following version to fix the vulnerability.

  • "region PAY" App for Android 1.5.28

Vendor Status

Vendor Status Last Update Vendor Notes
Gift Pad Co.,Ltd. Vulnerable 2025/07/22

References

JPCERT/CC Addendum

Vulnerability Analysis by JPCERT/CC

Credit

Kubo Naoki reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.

Other Information

JPCERT Alert
JPCERT Reports
CERT Advisory
CPNI Advisory
TRnotes
CVE CVE-2025-52580
JVN iPedia JVNDB-2025-000050