The device ID is based on IMEI in Forever KidsWatch Call...
Moderate severity
Unreviewed
Published
Feb 6, 2025
to the GitHub Advisory Database
•
Updated Feb 10, 2025
Description
Published by the National Vulnerability Database
Feb 6, 2025
Published to the GitHub Advisory Database
Feb 6, 2025
Last updated
Feb 10, 2025
The device ID is based on IMEI in Forever KidsWatch Call Me KW50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h and Forever KidsWatch Call Me 2 KW60 R36CW_YDE_S4_A29_2_V1.0_2023.05.24_22.49.44_cob_b. If a malicious user changes the IMEI to the IMEI of a unit they registered in the mobile app, it is possible to hijack the device and control it from the app.
References