CVE-2024-7206

HIGH

eWeLink Zigbee Bridge Pro <= 2.0.0 - SSL Pinning Bypass Secret Extraction

Title source: manual
STIX 2.1

Description

SSL Pinning Bypass in eWeLink Some hardware products allows local ATTACKER to Decrypt TLS communication and Extract secrets to clone the device via Flash the modified firmware

Scores

CVSS v4 7.0
EPSS 0.0023
EPSS Percentile 13.3%
CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-295 CWE-798
Status published
Products (1)
eWeLink/Zigbee Bridge Pro < 2.0.0
Published Oct 08, 2024
Tracked Since Feb 18, 2026