CVE-2024-3130: Coolkit Ewelink App

Medium severity, CVSS 5.7. EPSS: 0.1% chance of exploitation in the next 30 days.

Hard-coded Credentials in CoolKit eWeLlink app are before 5.4.x on Android and IOS allows local attacker to unauthorized access to sensitive data via Decryption algorithm and key obtained after decompiling app

Affected products

  • Coolkit Ewelink App: before 5.5 (fixed in 5.5)

Published 2024-04-01. Last modified 2026-06-17.