CVE ID | CVE-2023-6998 |
Publication date | 30 December 2023 |
Vendor | CoolKit Technology |
Product | eWeLink (Android & iOS) |
Vulnerable versions | All below 5.2.0 |
Vulnerability type (CWE) | Authentication Bypass by Primary Weakness (CWE-305) |
Report source | NASK own research |
Description
CERT Polska has received a report about vulnerability in eWeLink applications on platforms Android and iOS and participated in its coordination. The vulnerability allows application lockscreen bypass. The weakness has been confirmed by the vendor and assigned the number CVE-2023-6998. The vulnerability was fixed in versions 5.2.0, all below are vulnerable.
Credits
We thank Jan Adamski from NASK for the responsible vulnerability report.
More about the coordinated vulnerability disclosure process at CERT Polska can be found at https://cert.pl/en/cvd/.