The Zizai Tech Nut mobile app stores the account password used to authenticate to the cloud API in cleartext in the cache.db file.
The product stores sensitive information in cleartext in a file, or on disk.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://www.securityfocus.com/bid/93877 | vdb entry third party advisory |
https://blog.rapid7.com/2016/10/25/multiple-bluetooth-low-energy-ble-tracker-vulnerabilities/ | third party advisory exploit |
https://www.kb.cert.org/vuls/id/402847 | third party advisory us government resource |