Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4hq8-rhcf-fxwv

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Weak encryption in the Quick Pairing mode in the eWeLink mobile application (Android application V4.9.2 and earlier, iOS application V4.9.1 and earlier) allows physically proximate attackers to eavesdrop on Wi-Fi credentials and other sensitive information by monitoring the Wi-Fi spectrum during the pairing process.

Weak encryption in the Quick Pairing mode in the eWeLink mobile application (Android application V4.9.2 and earlier, iOS application V4.9.1 and earlier) allows physically proximate attackers to eavesdrop on Wi-Fi credentials and other sensitive information by monitoring the Wi-Fi spectrum during the pairing process.

EPSS

Процентиль: 62%
0.0043
Низкий

Дефекты

CWE-326

Связанные уязвимости

CVSS3: 4.6
nvd
почти 5 лет назад

Weak encryption in the Quick Pairing mode in the eWeLink mobile application (Android application V4.9.2 and earlier, iOS application V4.9.1 and earlier) allows physically proximate attackers to eavesdrop on Wi-Fi credentials and other sensitive information by monitoring the Wi-Fi spectrum during the pairing process.

EPSS

Процентиль: 62%
0.0043
Низкий

Дефекты

CWE-326