PT-2021-9428 · Unknown · Wiz Colors A60

Jasper Nota

+3

·

Published

2021-04-02

·

Updated

2024-07-30

·

CVE-2020-11922

CVSS v3.1

4.3

Medium

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions WiZ Colors A60 version 1.14.0
Description An issue was discovered where the device sends unnecessary information to the cloud controller server, including the local IP address and the SSID of the Wi-Fi network it is connected to. Although this information is sent encrypted, it decreases the privacy of the end user. The sent SSID can be mapped to physical locations using resources like wigle.net.
Recommendations For WiZ Colors A60 version 1.14.0, consider restricting the device's ability to send this unnecessary information to the cloud controller server as a temporary workaround until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2020-11922

Affected Products

Wiz Colors A60