Wink is a narrowly scoped smart-home automation and connectivity platform whose vulnerability profile concentrates in its core product around the storage and handling of sensitive configuration and authentication data. The recurring weakness classes—cleartext storage and insecure storage of sensitive information—reflect the challenges of protecting credentials and secrets in IoT and home-automation contexts. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wink over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-5249CRITICAL In version 6.1.0.19 and prior of Wink Labs's Wink - Smart Home Android app, the OAuth token used by the app to authorize user access is not stored in an encrypted and secure manner | Feb 22, 2018 | 9.8 | 29 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wink.
Media articles that mention a CVE ID that affects a product developed by Wink — matched by CVE ID, not by vendor name.