When the device is shared, the homepage module are before 2.19.0 in eWeLink Cloud Service allows Secondary user to take over devices as primary user via sharing unnecessary device-sensitive information.
When a device is shared with another user, the home page module transmits unnecessary, sensitive device information to the secondary user (CWE-201: Insertion of Sensitive Information Into Sent Data). The secondary user, using this information, is able to impersonate the owner and take full control of the device as the primary user.
An attacker with secondary user status can assume the role of the primary user and gain full control over the shared IoT device, which may lead to unauthorized device management and compromise of confidentiality and integrity of related data and systems.
Update eWeLink Cloud Service to version 2.19.0 or later. Detailed information is available in the official security advisory from the manufacturer at https://ewelink.cc/security-advisory-240730/
eWeLink Cloud Service home page module in versions prior to 2.19.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:N/R:U/V:D/RE:L/U:Green