In version 1.9.7 and prior of Insteons Insteon for Hub Android app, the OAuth token used by the app to authorize user access is not stored in an encrypted and secure manner.
The product stores sensitive information without properly limiting read or write access by unauthorized actors.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Insteon_for_hub | Insteon | * | 1.9.7 (including) |