Report an incident
Report an incident

Vulnerability in CoolKit Technology eWeLink mobile application (Android & iOS)
30 December 2023 | CERT Polska | #vulnerability, #warning, #cve
CVE ID CVE-2023-6998
Publication date 30 December 2023
Vendor CoolKit Technology
Product eWeLink (Android & iOS)
Vulnerable versions All below 5.2.0
Vulnerability type (CWE) Improper Privilege Management (CWE-269)
Report source NASK own research

Description

CERT Polska has received a report about vulnerability in eWeLink applications on platforms Android and iOS and participated in its coordination. The vulnerability allows application lockscreen bypass. The weakness has been confirmed by the vendor and assigned the number CVE-2023-6998. The vulnerability was fixed in versions 5.2.0, all below are vulnerable.

Credits

We thank Jan Adamski from NASK for the responsible vulnerability report.


More about the coordinated vulnerability disclosure process at CERT Polska can be found at https://cert.pl/en/cvd/.