CVE Vulnerabilities

CVE-2024-7206

Improper Certificate Validation

Published: Oct 08, 2024 | Modified: Oct 08, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

SSL Pinning Bypass in eWeLink Some hardware products allows local ATTACKER to Decrypt TLS communication and Extract secrets to clone the device via Flash the modified firmware

Weakness

The product does not validate, or incorrectly validates, a certificate.

Potential Mitigations

References