CVE-2021-27941
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Unconstrained Web access to the device's private encryption key in the QR code pairing mode in the eWeLink mobile application (through 4.9.2 on Android and through 4.9.1 on iOS) allows a physically proximate attacker to eavesdrop on Wi-Fi credentials and other sensitive information by monitoring the Wi-Fi spectrum during a device pairing process.
El acceso web sin restricciones a la clave de cifrado privada del dispositivo en el modo de emparejamiento de código QR en la aplicación móvil eWeLink (versiones hasta.9.2 en Android y versiones hasta.9.1 en iOS) permite a un atacante físicamente próximo espiar las credenciales de Wi-Fi y otras información mediante el seguimiento del espectro de Wi-Fi durante un proceso de emparejamiento de dispositivos
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-03-03 CVE Reserved
- 2021-05-06 CVE Published
- 2024-08-03 CVE Updated
- 2025-03-10 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-522: Insufficiently Protected Credentials
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
https://apps.apple.com/us/app/ewelink-smart-home/id1035163158 | Product | |
https://github.com/salgio/eWeLink-QR-Code | Third Party Advisory | |
https://play.google.com/store/apps/details?id=com.coolkit&hl=en_US | Product |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Coolkit Search vendor "Coolkit" | Ewelink Search vendor "Coolkit" for product "Ewelink" | <= 4.9.1 Search vendor "Coolkit" for product "Ewelink" and version " <= 4.9.1" | iphone_os |
Affected
| ||||||
Coolkit Search vendor "Coolkit" | Ewelink Search vendor "Coolkit" for product "Ewelink" | <= 4.9.2 Search vendor "Coolkit" for product "Ewelink" and version " <= 4.9.2" | android |
Affected
|