Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-36557

Опубликовано: 06 фев. 2025
Источник: nvd
CVSS3: 6.6
EPSS Низкий

Описание

The device ID is based on IMEI in Forever KidsWatch Call Me KW50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h and Forever KidsWatch Call Me 2 KW60 R36CW_YDE_S4_A29_2_V1.0_2023.05.24_22.49.44_cob_b. If a malicious user changes the IMEI to the IMEI of a unit they registered in the mobile app, it is possible to hijack the device and control it from the app.

EPSS

Процентиль: 19%
0.0006
Низкий

6.6 Medium

CVSS3

Дефекты

CWE-290

Связанные уязвимости

CVSS3: 6.6
github
около 1 года назад

The device ID is based on IMEI in Forever KidsWatch Call Me KW50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h and Forever KidsWatch Call Me 2 KW60 R36CW_YDE_S4_A29_2_V1.0_2023.05.24_22.49.44_cob_b. If a malicious user changes the IMEI to the IMEI of a unit they registered in the mobile app, it is possible to hijack the device and control it from the app.

EPSS

Процентиль: 19%
0.0006
Низкий

6.6 Medium

CVSS3

Дефекты

CWE-290