CVE-2023-34761: 7-Eleven Hello Cup

Medium severity, CVSS 6.5. EPSS: 0.5% chance of exploitation in the next 30 days.

An unauthenticated attacker within BLE proximity can remotely connect to a 7-Eleven LED Message Cup, Hello Cup 1.3.1 for Android, and bypass the application's client-side chat censor filter.

Affected products

Published 2023-06-28. Last modified 2026-06-17.