CVE-2024-7206
HIGHeWeLink Zigbee Bridge Pro <= 2.0.0 - SSL Pinning Bypass Secret Extraction
Title source: manualDescription
SSL Pinning Bypass in eWeLink Some hardware products allows local ATTACKER to Decrypt TLS communication and Extract secrets to clone the device via Flash the modified firmware
References (1)
Core 1
Core References
Scores
CVSS v4
7.0
EPSS
0.0023
EPSS Percentile
13.3%
CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-295
CWE-798
Status
published
Products (1)
eWeLink/Zigbee Bridge Pro
< 2.0.0
Published
Oct 08, 2024
Tracked Since
Feb 18, 2026