> OTP Disclosure via Exported TokenContentProvider
[DATE: 12/05/2026 07:00]
[LANGUAGE: EN]
CVSSv3 Score:
5.0
An improper export of Android application components [CWE-926] in FortiTokenAndroid may allow other applications on the device to read the OTP code via an exported Content Provider URI.
Revised on 2026-05-12 00:00:00