CVE-2024-3130

MEDIUM

CoolKit eWeLlink <5.4.x - Info Disclosure

Title source: llm
STIX 2.1

Description

Hard-coded Credentials in CoolKit eWeLlink app are before 5.4.x on Android and IOS allows local attacker to unauthorized access to sensitive data via Decryption algorithm and key obtained after decompiling app

References (1)

Core 1
Core References

Scores

CVSS v3 5.7
EPSS 0.0014
EPSS Percentile 3.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-798
Status published
Products (1)
CoolKIt/eWeLink APP < 5.4.x
Published Apr 01, 2024
Tracked Since Feb 18, 2026