CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2024-7205

CVSS 9.4v4.0pub. 2024-07-31upd. 2026-04-15

When the device is shared, the homepage module are before 2.19.0  in eWeLink Cloud Service allows Secondary user to take over devices as primary user via sharing unnecessary device-sensitive information.

🤖 AI Analysis
How it works

When a device is shared with another user, the home page module transmits unnecessary, sensitive device information to the secondary user (CWE-201: Insertion of Sensitive Information Into Sent Data). The secondary user, using this information, is able to impersonate the owner and take full control of the device as the primary user.

Impact

An attacker with secondary user status can assume the role of the primary user and gain full control over the shared IoT device, which may lead to unauthorized device management and compromise of confidentiality and integrity of related data and systems.

Mitigation & patch

Update eWeLink Cloud Service to version 2.19.0 or later. Detailed information is available in the official security advisory from the manufacturer at https://ewelink.cc/security-advisory-240730/

Who is affected

eWeLink Cloud Service home page module in versions prior to 2.19.0

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:N/R:U/V:D/RE:L/U:Green
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
References