QID 630787
QID 630787: For Android Vulnerability CVE-2021-44518
An issue was discovered in the eGeeTouch 3rd Generation Travel Padlock application for Android. The lock sends a pairing code before each operation (lock or unlock) activated via the companion app. The code is sent unencrypted, allowing any attacker with the same app (either Android or iOS) to add the lock and take complete control. For successful exploitation, the attacker must be able to touch the lock's power button, and must be able to capture BLE network communication.
On successful exploitation, it could allow an attacker to execute code.
Solution
Upgrade to the latest packages which contain a patch. Refer to CVE-2021-44518 to address this issue and obtain more information.
Vendor References
- CVE-2021-44518 -
nvd.nist.gov/vuln/detail/CVE-2021-44518
CVEs related to QID 630787
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2021-44518 | Android |
|