Elemental Path's CogniToys Dino smart toys through firmware version 0.0.794 share a fixed small pool of hardcoded keys, allowing a remote attacker to use a different Dino device to decrypt VoIP traffic between a child's Dino and remote server.
The product uses a broken or risky cryptographic algorithm or protocol.
Link | Tags |
---|---|
https://dl.acm.org/citation.cfm?id=3139947 | third party advisory issue tracking |