CVE-2019-16518: Vandyvape Swell Kit Mod Firmware

Medium severity, CVSS 4.3. EPSS: 0.6% chance of exploitation in the next 30 days.

An issue was discovered on Swell Kit Mod devices that use the Vandy Vape platform. An attacker may be able to trigger an unintended temperature in the victim's mouth and throat via Bluetooth Low Energy (BLE) packets that specify large power or voltage values.

Affected products

  • Vandyvape Swell Kit Mod Firmware: version 2.0.2 only

Published 2019-09-23. Last modified 2026-06-17.