Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2r8x-g2v5-x892

Опубликовано: 06 фев. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 6.6

Описание

The device ID is based on IMEI in Forever KidsWatch Call Me KW50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h and Forever KidsWatch Call Me 2 KW60 R36CW_YDE_S4_A29_2_V1.0_2023.05.24_22.49.44_cob_b. If a malicious user changes the IMEI to the IMEI of a unit they registered in the mobile app, it is possible to hijack the device and control it from the app.

The device ID is based on IMEI in Forever KidsWatch Call Me KW50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h and Forever KidsWatch Call Me 2 KW60 R36CW_YDE_S4_A29_2_V1.0_2023.05.24_22.49.44_cob_b. If a malicious user changes the IMEI to the IMEI of a unit they registered in the mobile app, it is possible to hijack the device and control it from the app.

EPSS

Процентиль: 19%
0.0006
Низкий

6.6 Medium

CVSS3

Дефекты

CWE-290

Связанные уязвимости

CVSS3: 6.6
nvd
около 1 года назад

The device ID is based on IMEI in Forever KidsWatch Call Me KW50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h and Forever KidsWatch Call Me 2 KW60 R36CW_YDE_S4_A29_2_V1.0_2023.05.24_22.49.44_cob_b. If a malicious user changes the IMEI to the IMEI of a unit they registered in the mobile app, it is possible to hijack the device and control it from the app.

EPSS

Процентиль: 19%
0.0006
Низкий

6.6 Medium

CVSS3

Дефекты

CWE-290