Skip to main content

Incorrect Resource Transfer Between Spheres

CVE-2025-56675

Severity Low
Score 3.5/10

Summary

The EKEN video doorbell T6 BT60PLUS_MAIN_V1.0_GC1084_20230531 periodically sends debug logs to the EKEN cloud servers with sensitive information such as the Wi-Fi SSID and password.

  • HIGH
  • NETWORK
  • NONE
  • CHANGED
  • NONE
  • LOW
  • LOW
  • NONE

CWE-669 - Incorrect Resource Transfer Between Spheres

The product does not properly transfer a resource/behavior to another sphere, or improperly imports a resource/behavior from another sphere, in a manner that provides unintended control over that resource.

References

Advisory Timeline

  • Published