mirror of
https://github.com/0xMarcio/cve.git
synced 2026-06-02 20:21:38 +02:00
23 lines
1022 B
Markdown
23 lines
1022 B
Markdown
### [CVE-2020-12702](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-12702)
|
|

|
|

|
|

|
|
|
|
### Description
|
|
|
|
Weak encryption in the Quick Pairing mode in the eWeLink mobile application (Android application V4.9.2 and earlier, iOS application V4.9.1 and earlier) allows physically proximate attackers to eavesdrop on Wi-Fi credentials and other sensitive information by monitoring the Wi-Fi spectrum during the pairing process.
|
|
|
|
### POC
|
|
|
|
#### Reference
|
|
- https://www.youtube.com/watch?v=DghYH7WY6iE&feature=youtu.be
|
|
|
|
#### Github
|
|
- https://github.com/ARPSyndicate/cvemon
|
|
- https://github.com/developer3000S/PoC-in-GitHub
|
|
- https://github.com/nomi-sec/PoC-in-GitHub
|
|
- https://github.com/salgio/ESPTouchCatcher
|
|
- https://github.com/salgio/eWeLink-QR-Code
|
|
- https://github.com/soosmile/POC
|
|
|