Description
Smart-tab Android app installed April 2023 or earlier contains an issue with plaintext storage of a password. If this vulnerability is exploited, an attacker with physical access to the device may retrieve the credential information and spoof the device to access the related external service.
Scores
CVSS v3
2.4
EPSS
0.0015
EPSS Percentile
34.6%
Attack Vector
PHYSICAL
CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-256
Status
published
Products (1)
TECHNO SUPPORT COMPANY/Smart-tab Android app
installed April 2023 or earlier
Published
Sep 30, 2024
Tracked Since
Feb 18, 2026