Description
An issue was discovered in WiZ Colors A60 1.14.0. The device sends unnecessary information to the cloud controller server. Although this information is sent encrypted and has low risk in isolation, it decreases the privacy of the end user. The information sent includes the local IP address being used and the SSID of the Wi-Fi network the device is connected to. (Various resources such as wigle.net can be use for mapping of SSIDs to physical locations.)
Published: 2021-04-02
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2020-4259 An issue was discovered in WiZ Colors A60 1.14.0. The device sends unnecessary information to the cloud controller server. Although this information is sent encrypted and has low risk in isolation, it decreases the privacy of the end user. The information sent includes the local IP address being used and the SSID of the Wi-Fi network the device is connected to. (Various resources such as wigle.net can be use for mapping of SSIDs to physical locations.)
History

No history.

Subscriptions

Wizconnected A60 Colors A60 Colors Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-04T11:42:00.756Z

Reserved: 2020-04-19T00:00:00.000Z

Link: CVE-2020-11922

cve-icon Vulnrichment

Updated: 2024-08-04T11:42:00.756Z

cve-icon NVD

Status : Modified

Published: 2021-04-02T16:15:13.507

Modified: 2024-11-21T04:58:54.733

Link: CVE-2020-11922

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses