An issue was discovered in WiZ Colors A60 1.14.0. Wi-Fi credentials are stored in cleartext in flash memory, which presents an information-disclosure risk for a discarded or resold device.
References
Link | Resource |
---|---|
https://www.eurofins-cybersecurity.com/news/connected-devices-wiz-smart-lightbulbs/ | Exploit Third Party Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Information
Published : 2021-04-02 12:15
Updated : 2021-04-07 12:30
NVD link : CVE-2020-11924
Mitre link : CVE-2020-11924
JSON object : View
CWE
CWE-312
Cleartext Storage of Sensitive Information
Products Affected
wizconnected
- colors_a60
- colors_a60_firmware