CVE-2026-3668 identifies an improper access control vulnerability within the AndroidEthereum function of the org.ethosmobile.webpwaemul component in Freedom Factory dGEN1, affecting versions up to 20260221. This vulnerability has a CVSS 3.1 score of LOW, indicating a low impact with potential for remote exploitation, though the attack complexity is high and exploitability is difficult. While public exploit code exists, there is no evidence of active exploitation, and it has garnered minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Freedom Factory | DGEN1 | 20260221CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.2 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.1 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.