CVE-2024-7205

EUVD-2024-48173
When the device is shared, the homepage module are before 2.19.0  in eWeLink Cloud Service allows Secondary user to take over devices as primary user via sharing unnecessary device-sensitive information.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.4 CRITICAL
NETWORK
LOW
NONE
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/S:P/AU:N/R:U/V:D/RE:L/U:Green
Base Score
CVSS 3.x
EPSS Score
Percentile: 42%
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
coolkitewelink
𝑥
< 2.19.0
ADP