4.6

CVE-2021-27941

Unconstrained Web access to the device's private encryption key in the QR code pairing mode in the eWeLink mobile application (through 4.9.2 on Android and through 4.9.1 on iOS) allows a physically proximate attacker to eavesdrop on Wi-Fi credentials and other sensitive information by monitoring the Wi-Fi spectrum during a device pairing process.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
CoolkitEwelink SwPlatformiphone_os Version <= 4.9.1
CoolkitEwelink SwPlatformandroid Version <= 4.9.2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.21% 0.116
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.6 0.9 3.6
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvd@nist.gov 2.1 3.9 2.9
AV:L/AC:L/Au:N/C:P/I:N/A:N
CWE-522 Insufficiently Protected Credentials

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

https://play.google.com/store/apps/details?id=com.coolkit&hl=en_US
Third Party Advisory
Product
https://apps.apple.com/us/app/ewelink-smart-home/id1035163158
Third Party Advisory
Product
https://github.com/salgio/eWeLink-QR-Code
Third Party Advisory