1 results (0.003 seconds)
CVSS: 9.4EPSS: 0%CPEs: 1EXPL: 0

CVE-2024-7205 – sharing unnecessary device-sensitive information allows Secondary user able to take over devices as primary user
https://notcve.org/view.php?id=CVE-2024-7205
31 Jul 2024 — When the device is shared, the homepage module are before 2.19.0 in eWeLink Cloud Service allows Secondary user to take over devices as primary user via sharing unnecessary device-sensitive information. When the device is shared, the homepage module are before 2.19.0 in eWeLink Cloud Service allows Secondary user to take over devices as primary user via sharing unnecessary device-sensitive information. • https://ewelink.cc/security-advisory-240730 • CWE-201: Insertion of Sensitive Information Into Sent Data •