Security Advisory – eWeLink 2.4G remote control light bulbs Remote Code Execution Vulnerability

TitleSecurity Advisory – eWeLink 2.4G remote control light bulbs Remote Code Execution Vulnerability
Release Date2023/11/07
AbstractThe connection modules of some Bluetooth 2.4G remote-control devices contain a vulnerability that allows bypassing of authentication. Successfully exploiting this vulnerability may allow attackers to access restricted functionalities.
Affected ProductBLREAD-L
Affected VersionBLREAD-L 1.2.1
ImpactAttackers can exploit this vulnerability to access certain restricted functionalities.
Technical DetailsExploitation Preconditions: The attacker is in proximity to the device and successfully pairs with the target device using the eWeLink App.

Technical Details: Some "Bluetooth 2.4G remote-control lights" have a vulnerability that bypasses authentication. Connection to the device can be achieved without user authorization. Successfully exploiting this vulnerability may allow access to certain functionalities.
ResolutionUpdate the device’s firmware via eWeLink App to 1.2.2 or later.

This website use cookies to ensure you get the best experience on our website.