Hard-coded Credentials in CoolKit eWeLlink app are before 5.4.x on Android and IOS allows local attacker to unauthorized access to sensitive data via Decryption algorithm and key obtained after decompiling app
History

Wed, 12 Mar 2025 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Coolkit
Coolkit ewelink App
CPEs cpe:2.3:a:coolkit:ewelink_app:*:*:*:*:*:*:*:*
Vendors & Products Coolkit
Coolkit ewelink App
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: CoolKit

Published:

Updated: 2025-03-12T16:46:05.674Z

Reserved: 2024-04-01T09:11:45.225Z

Link: CVE-2024-3130

cve-icon Vulnrichment

Updated: 2024-08-01T19:32:42.974Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-04-01T10:15:07.607

Modified: 2025-03-12T17:15:42.110

Link: CVE-2024-3130

cve-icon Redhat

No data.