CVE-2024-36554
Published: 06 February 2025
Description
Forever KidsWatch Call Me KW-50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h and Forever KidsWatch Call Me KW-60 R36CW_YDE_S4_A29_2_V1.0_2023.05.24_22.49.44_cob_b allow a malicious user to gain information about the device by sending an SMS to the device which returns sensitive information.
Security Summary
CVE-2024-36554 affects two specific firmware versions of Forever KidsWatch devices: the Call Me KW-50 running R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h and the Call Me KW-60 running R36CW_YDE_S4_A29_2_V1.0_2023.05.24_22.49.44_cob_b. The vulnerability enables a malicious user to obtain sensitive information about the device by sending an SMS message, which prompts the device to return that data. It is rated critical with a CVSS v3.1 base score of 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) and is associated with CWE-497 (Exposure of Sensitive System Information to an Unauthorized Control Sphere). The CVE was published on 2025-02-06.
Any remote attacker can exploit this vulnerability without authentication, privileges, or user interaction by simply sending an SMS to the targeted device. Successful exploitation allows the attacker to retrieve sensitive device information, with high impacts on confidentiality, integrity, and availability as indicated by the CVSS vector.
A referenced research document details exploiting vulnerabilities, including this one, to remotely hijack children's smartwatches, available at https://www.diva-portal.org/smash/record.jsf?aq2=%5B%5B%5D%5D&c=1&af=%5B%5D&searchType=SIMPLE&sortOrder2=title_sort_asc&query=Exploiting+Vulnerabilities+to+Remotely+Hijack+Children%E2%80%99s+Smartwatches&language=en&pid=diva2%3A1933447&aq=%5B%5B%5D%5D&sf=undergraduate&aqe=%5B%5D&sortOrder=author_sort_asc&onlyFullText=false&noOfRows=50&dswid=-8296. No vendor advisories or patches are detailed in available information.
Details
- CWE(s)