SHENZHEN CoolKit Technology CO., LTD.
Self-Reporting Analysis
Of all the CVEs published by SHENZHEN CoolKit Technology CO., LTD. as a CNA, 0.0% affect products that SHENZHEN CoolKit Technology CO., LTD. develops as a vendor.
Of all the CVEs published that affect products developed by SHENZHEN CoolKit Technology CO., LTD., 0.0% are self-published by SHENZHEN CoolKit Technology CO., LTD. as a CNA.
Trends Over Time
The number and severity of CVEs published by SHENZHEN CoolKit Technology CO., LTD. over time
Top CVEs
All CVEs published by SHENZHEN CoolKit Technology CO., LTD. as a CNA, regardless of affected vendor or product.
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-7205CRITICAL When the device is shared, the homepage module are before 2.19.0 in eWeLink Cloud Service allows Secondary user to take over devices as primary user via sharing unnecessary device | Jul 31, 2024 | 9.4 | 28 | NO | NO |
CVE-2024-7206HIGH SSL Pinning Bypass in eWeLink Some hardware products allows local ATTACKER to Decrypt TLS communication and Extract secrets to clone the device via Flash the modified firmware | Oct 8, 2024 | 7.0 | 21 | NO | NO |
CVE-2024-3130MEDIUM Hard-coded Credentials in CoolKit eWeLlink app are before 5.4.x on Android and IOS allows local attacker to unauthorized access to sensitive data via Decryption algorithm and key o | Apr 1, 2024 | 5.7 | 18 | NO | NO |
CVE Severity & Scoring
Exploit Exposure
Signals from CVEs in this cna scope (3 CVEs).
Social Chatter
An overview of all social media posts that mention a CVE ID published by SHENZHEN CoolKit Technology CO., LTD. as a CNA.
Media Mentions
Media articles that mention a CVE ID published by SHENZHEN CoolKit Technology CO., LTD. as a CNA — matched by CVE ID, not by organization name.