Shenzhen CoolKit Technology operates eWeLink, an IoT connectivity and smart-home cloud platform, where its disclosed vulnerabilities center on authentication and credential-handling weaknesses including authentication bypass, insufficient credential protection, and use of broken cryptographic algorithms. These flaws reflect the attack surface inherent to cloud-based device management and remote-access services. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by SHENZHEN CoolKit Technology CO., LTD. over time
Of all the CVEs published by SHENZHEN CoolKit Technology CO., LTD. as a CNA, 0.0% affect products that SHENZHEN CoolKit Technology CO., LTD. develops as a vendor.
Of all the CVEs published that affect products developed by SHENZHEN CoolKit Technology CO., LTD., 0.0% are self-published by SHENZHEN CoolKit Technology CO., LTD. as a CNA.
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-6998HIGH Improper privilege management vulnerability in CoolKit Technology eWeLink on Android and iOS allows application lockscreen bypass.This issue affects eWeLink before 5.2.0. | Dec 30, 2023 | 7.7 | 22 | NO | NO |
CVE-2021-27941MEDIUM Unconstrained Web access to the device's private encryption key in the QR code pairing mode in the eWeLink mobile application (through 4.9.2 on Android and through 4.9.1 on iOS) al | May 6, 2021 | 4.6 | 18 | NO | NO |
CVE-2020-12702MEDIUM Weak encryption in the Quick Pairing mode in the eWeLink mobile application (Android application V4.9.2 and earlier, iOS application V4.9.1 and earlier) allows physically proximate | Feb 24, 2021 | 4.6 | 16 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by SHENZHEN CoolKit Technology CO., LTD..
Media articles that mention a CVE ID that affects a product developed by SHENZHEN CoolKit Technology CO., LTD. — matched by CVE ID, not by vendor name.