CVE-2024-25731: Elinksmart Esmartcam
High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.
The Elink Smart eSmartCam (com.cn.dq.ipc) application 2.1.5 for Android contains hardcoded AES encryption keys that can be extracted from a binary file. Thus, encryption can be defeated by an attacker who can observe packet data (e.g., over Wi-Fi).
Affected products
- Elinksmart Esmartcam: version 2.1.5 only
Published 2024-03-05. Last modified 2026-06-17.