CoolKIt records
4 published records for vendor coolkit.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-201 Insertion of Sensitive Information Into Sent Data1
- CWE-305 Authentication Bypass by Primary Weakness1
- CWE-327 Use of a Broken or Risky Cryptographic Algorithm1
- CWE-522 Insufficiently Protected Credentials1
The weakness classes this vendor ships most often: where to look.
CWEAll records
4 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
37Monitor | CVE-2024-7205No exploit | sharing unnecessary device-sensitive information allows Secondary user able to take over devices as primary usercoolkit · ewelink cloud service · CWE-201 | Critical9.4 | — | 0.5% | Jul 31, 2024 |
30Monitor | CVE-2023-6998No exploit | Lockscreen bypass in eWeLink Appcoolkit · ewelink · CWE-305 | High7.7 | — | 0.2% | Dec 30, 2023 |
18Monitor | CVE-2020-12702Proof of concept | Weak encryption in the Quick Pairing mode in the eWeLink mobile application (Android application V4.9.2 and earlier, iOS application V4.9.1 coolkit · ewelink · CWE-327 | Medium4.6 | — | 0.3% | Feb 24, 2021 |
18Monitor | CVE-2021-27941No exploit | Unconstrained Web access to the device's private encryption key in the QR code pairing mode in the eWeLink mobile application (through 4.9.2coolkit · ewelink · CWE-522 | Medium4.6 | — | 0.2% | May 6, 2021 |
- CVE-2024-720537Monitor
sharing unnecessary device-sensitive information allows Secondary user able to take over devices as primary user
CriticalCVSS 9.4No exploitEPSS 0%coolkit · ewelink cloud serviceJul 31, 2024
- CVE-2023-699830Monitor
Lockscreen bypass in eWeLink App
HighCVSS 7.7No exploitEPSS 0%coolkit · ewelinkDec 30, 2023
- CVE-2020-1270218Monitor
Weak encryption in the Quick Pairing mode in the eWeLink mobile application (Android application V4.9.2 and earlier, iOS application V4.9.1
MediumCVSS 4.6Proof of conceptEPSS 0%coolkit · ewelinkFeb 24, 2021
- CVE-2021-2794118Monitor
Unconstrained Web access to the device's private encryption key in the QR code pairing mode in the eWeLink mobile application (through 4.9.2
MediumCVSS 4.6No exploitEPSS 0%coolkit · ewelinkMay 6, 2021