Description
Hard-coded Credentials in CoolKit eWeLlink app are before 5.4.x on Android and IOS allows local attacker to unauthorized access to sensitive data via Decryption algorithm and key obtained after decompiling app

Published: 2024-04-01
Score: 5.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

Update to the latest version of the app.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2024-31731 Hard-coded Credentials in CoolKit eWeLlink app are before 5.4.x on Android and IOS allows local attacker to unauthorized access to sensitive data via Decryption algorithm and key obtained after decompiling app
History

Wed, 27 Aug 2025 22:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:coolkit:ewelink_app:*:*:*:*:*:*:*:*
Vendors & Products Coolkit
Coolkit ewelink App

Wed, 12 Mar 2025 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Coolkit
Coolkit ewelink App
CPEs cpe:2.3:a:coolkit:ewelink_app:*:*:*:*:*:*:*:*
Vendors & Products Coolkit
Coolkit ewelink App
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: CoolKit

Published:

Updated: 2025-08-27T21:23:01.088Z

Reserved: 2024-04-01T09:11:45.225Z

Link: CVE-2024-3130

cve-icon Vulnrichment

Updated: 2024-08-01T19:32:42.974Z

cve-icon NVD

Status : Deferred

Published: 2024-04-01T10:15:07.607

Modified: 2026-04-15T00:35:42.020

Link: CVE-2024-3130

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses