CVE-2024-36555

Built-in SMS-configuration command in Forever KidsWatch Call Me KW50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h and Forever KidsWatch Call Me 2 KW-60 R36CW_YDE_S4_A29_2_V1.0_2023.05.24_22.49.44_cob_b allows malicious users to change the device IMEI-number which allows for forging the identity of the device.
Configurations

No configuration.

History

10 Feb 2025, 15:15

Type Values Removed Values Added
CWE CWE-306
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
Summary
  • (es) El comando de configuración de SMS integrado en Forever KidsWatch Call Me KW50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h y Forever KidsWatch Call Me 2 KW-60 R36CW_YDE_S4_A29_2_V1.0_2023.05.24_22.49.44_cob_b permite a usuarios malintencionados cambiar el número IMEI del dispositivo, lo que permite falsificar la identidad del dispositivo.

06 Feb 2025, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-06 18:15

Updated : 2025-02-10 15:15


NVD link : CVE-2024-36555

Mitre link : CVE-2024-36555

CVE.ORG link : CVE-2024-36555


JSON object : View

Products Affected

No product.

CWE
CWE-306

Missing Authentication for Critical Function