CVE-2024-3130

Hard-coded Credentials in CoolKit eWeLlink app are before 5.4.x on Android and IOS allows local attacker to unauthorized access to sensitive data via Decryption algorithm and key obtained after decompiling app
Configurations

No configuration.

History

21 Nov 2024, 09:28

Type Values Removed Values Added
Summary
  • (es) Las credenciales codificadas en la aplicación CoolKit eWeLlink son anteriores a 5.4.x en Android e IOS, lo que permite a un atacante local acceder no autorizado a datos confidenciales a través del algoritmo de descifrado y la clave obtenida después de descompilar la aplicación.
References () https://ewelink.cc/security-advisories-and-notices/ - () https://ewelink.cc/security-advisories-and-notices/ -

01 Apr 2024, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-04-01 10:15

Updated : 2025-03-12 17:15


NVD link : CVE-2024-3130

Mitre link : CVE-2024-3130

CVE.ORG link : CVE-2024-3130


JSON object : View

Products Affected

No product.

CWE
CWE-798

Use of Hard-coded Credentials