CVE-2021-27941
Unconstrained Web access to the device's private encryption key in the QR code pairing mode in the eWeLink mobile application (through 4.9.2 on Android and through 4.9.1 on iOS) allows a physically proximate attacker to eavesdrop on Wi-Fi credentials…
Does this matter?
Lower severity and a low EPSS score (0.21%). Track it; it rarely justifies an emergency change on its own.
Description
Unconstrained Web access to the device's private encryption key in the QR code pairing mode in the eWeLink mobile application (through 4.9.2 on Android and through 4.9.1 on iOS) allows a physically proximate attacker to eavesdrop on Wi-Fi credentials and other sensitive information by monitoring the Wi-Fi spectrum during a device pairing process.
- CVSS 3.1
- 4.6 MEDIUMCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.21% probability · 12th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-522
- Affected
- coolkit/ewelink
- Source
- cve@mitre.org
References
- https://apps.apple.com/us/app/ewelink-smart-home/id1035163158Product, Third Party Advisory
- https://github.com/salgio/eWeLink-QR-CodeThird Party Advisory
- https://play.google.com/store/apps/details?id=com.coolkit&hl=en_USProduct, Third Party Advisory
- https://apps.apple.com/us/app/ewelink-smart-home/id1035163158Product, Third Party Advisory
- https://github.com/salgio/eWeLink-QR-CodeThird Party Advisory
- https://play.google.com/store/apps/details?id=com.coolkit&hl=en_USProduct, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.