Vulnerability CVE-2022-37857


Published: 2022-09-08

Description:
bilde2910 Hauk v1.6.1 requires a hardcoded password which by default is blank. This hardcoded password is hashed but stored within the config.php file server-side as well as in clear-text on the android client device by default.

 References:
https://github.com/bilde2910/Hauk/issues/187
https://gainsec.com/2022/08/07/cve-2022-hardcoded-creds-weak-password-hauk-android-location-sharing/

Copyright 2026, cxsecurity.com

 

Back to Top