CVE-2024-7205: Coolkit Ewelink
Critical severity, CVSS 9.4. EPSS: 0.5% chance of exploitation in the next 30 days.
When the device is shared, the homepage module are before 2.19.0 in eWeLink Cloud Service allows Secondary user to take over devices as primary user via sharing unnecessary device-sensitive information.
Affected products
- Coolkit Ewelink: before 2.19.0 (fixed in 2.19.0)
- Coolkit Ewelink Cloud Service: from 2.0.0, before 2.19.0 (fixed in 2.19.0)
Published 2024-07-31. Last modified 2026-06-17.