CVE-2021-27941

CVE-2021-27941

Unconstrained Web access to the device’s private encryption key in the QR code pairing mode in the eWeLink mobile application (through 4.9.2 on Android and through 4.9.1 on iOS) allows a physically proximate attacker to eavesdrop on Wi-Fi credentials and other sensitive information by monitoring the Wi-Fi spectrum during a device pairing process.

Source: CVE-2021-27941

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다