When the device is shared, the homepage module are before 2.19.0 in eWeLink Cloud Service allows Secondary user to take over devices as primary user via sharing unnecessary device-sensitive information.
CVSS
No CVSS.
References
Link | Resource |
---|---|
https://ewelink.cc/security-advisory-240730/ |
Configurations
No configuration.
History
31 Jul 2024, 12:57
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
31 Jul 2024, 06:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-07-31 06:15
Updated : 2024-07-31 15:15
NVD link : CVE-2024-7205
Mitre link : CVE-2024-7205
CVE.ORG link : CVE-2024-7205
JSON object : View
Products Affected
No product.
CWE
CWE-201
Insertion of Sensitive Information Into Sent Data