CVE-2024-3130: Coolkit Ewelink App
Medium severity, CVSS 5.7. EPSS: 0.1% chance of exploitation in the next 30 days.
Hard-coded Credentials in CoolKit eWeLlink app are before 5.4.x on Android and IOS allows local attacker to unauthorized access to sensitive data via Decryption algorithm and key obtained after decompiling app
Affected products
- Coolkit Ewelink App: before 5.5 (fixed in 5.5)
Published 2024-04-01. Last modified 2026-06-17.