CVE-2021-28372 describes a critical vulnerability in ThroughTek's Kalay Platform 2.0 SDK, affecting numerous IoT devices, particularly IP cameras and surveillance systems. An attacker can impersonate a legitimate device using a valid 20-byte UID, potentially hijacking connections and forcing credential disclosure. This vulnerability carries a high CVSS score of 8.3, indicating a network-based attack with high impact on confidentiality, integrity, and availability, though it requires user interaction and has high attack complexity. While there is no public exploit code or evidence of active exploitation, the vulnerability has garnered significant community discussion and media coverage, highlighting its potential widespread impact.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.1.10CPE matchmatch criteria | cpe:2.3:a:throughtek:kalay_p2p_software_development_kit:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.2 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.6 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.