CVE-2024-7205

Published Jul 31, 2024

Last updated a year ago

CVSS critical 9.4
eWeLink Cloud Service

Overview

AI description

Automated description summarized from trusted sources.

CVE-2024-7205 affects the eWeLink Cloud Service homepage module in versions before 2.19.0. The vulnerability allows a secondary user to take over devices as the primary user. This is achieved by sharing unnecessary device-sensitive information. To resolve this vulnerability, users should update the homepage module in eWeLink Cloud Service to version 2.19.0 or later. This patch was made available on July 30, 2024.

Description
When the device is shared, the homepage module are before 2.19.0  in eWeLink Cloud Service allows Secondary user to take over devices as primary user via sharing unnecessary device-sensitive information.
Source
68870bb1-d075-4169-957d-e580b18692b9
NVD status
Awaiting Analysis
CNA Tags
exclusively-hosted-service

Risk scores

CVSS 4.0

Type
Secondary
Base score
9.4
Impact score
-
Exploitability score
-
Vector string
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:N/R:U/V:D/RE:L/U:Green
Severity
CRITICAL

Weaknesses

68870bb1-d075-4169-957d-e580b18692b9
CWE-201

Social media

Hype score
Not currently trending

References

Sources include official advisories and independent security research.