PT-2021-24119 · Unknown · Egeetouch 3Rd Generation Travel Padlock

Ash Allen

·

Published

2021-12-02

·

Updated

2022-10-27

·

CVE-2021-44518

CVSS v2.0

2.9

Low

VectorAV:A/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions: eGeeTouch 3rd Generation Travel Padlock application for Android (affected versions not specified)
Description: An issue was discovered in the eGeeTouch 3rd Generation Travel Padlock application for Android. The lock sends a pairing code before each operation (lock or unlock) activated via the companion app. The code is sent unencrypted, allowing any attacker with the same app (either Android or iOS) to add the lock and take complete control. For successful exploitation, the attacker must be able to touch the lock's power button, and must be able to capture BLE network communication.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Cleartext Transmission of Sensitive Information

Weakness Enumeration

Related Identifiers

CVE-2021-44518

Affected Products

Egeetouch 3Rd Generation Travel Padlock