Skip to content
Noroxi

CoolKIt records

4 published records for vendor coolkit.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
0%
Median publish → KEV
No record has entered KEV

All records

4 records
  • CVE-2024-7205
    37Monitor

    sharing unnecessary device-sensitive information allows Secondary user able to take over devices as primary user

    CriticalCVSS 9.4No exploitEPSS 0%

    coolkit · ewelink cloud serviceJul 31, 2024

  • CVE-2023-6998
    30Monitor

    Lockscreen bypass in eWeLink App

    HighCVSS 7.7No exploitEPSS 0%

    coolkit · ewelinkDec 30, 2023

  • Weak encryption in the Quick Pairing mode in the eWeLink mobile application (Android application V4.9.2 and earlier, iOS application V4.9.1

    MediumCVSS 4.6Proof of conceptEPSS 0%

    coolkit · ewelinkFeb 24, 2021

  • Unconstrained Web access to the device's private encryption key in the QR code pairing mode in the eWeLink mobile application (through 4.9.2

    MediumCVSS 4.6No exploitEPSS 0%

    coolkit · ewelinkMay 6, 2021