VYPR
Medium severity4.6NVD Advisory· Published May 6, 2021· Updated Jun 17, 2026

CVE-2021-27941

CVE-2021-27941

Description

Unconstrained Web access to the device's private encryption key in the QR code pairing mode in the eWeLink mobile application (through 4.9.2 on Android and through 4.9.1 on iOS) allows a physically proximate attacker to eavesdrop on Wi-Fi credentials and other sensitive information by monitoring the Wi-Fi spectrum during a device pairing process.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • CoolKit/Ewelink2 versions
    cpe:2.3:a:coolkit:ewelink:*:*:*:*:*:android:*:*+ 1 more
    • cpe:2.3:a:coolkit:ewelink:*:*:*:*:*:android:*:*range: <=4.9.2
    • cpe:2.3:a:coolkit:ewelink:*:*:*:*:*:iphone_os:*:*range: <=4.9.1
  • eWeLink/eWeLink mobile applicationdescription
  • eWeLink/eWeLinkllm-fuzzy
    Range: <=4.9.2 on Android, <=4.9.1 on iOS

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.