CVE-2026-75553
2.4
CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Summary
Smartphone application Tohoku Electric Power "Yorisou e Net" uses a hard-coded cryptographic key, which may allow an attacker to retrieve a hard-coded cryptographic key from the affected product.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Tohoku Electric Power Company, Incorporated | Tohoku Electric Power “Yorisou e Net” Android App | 0 < 2.8.0 | affected |
| Tohoku Electric Power Company, Incorporated | Tohoku Electric Power “Yorisou e Net” iOS App | 0 < 2.8.0 | affected |
Weaknesses
- CWE-321: Use of hard-coded cryptographic key
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: no
- Technical Impact: partial
References
- https://play.google.com/store/apps/details?id=jp.co.tohokuepco.enet&hl=ja
- https://apps.apple.com/jp/app/%E6%9D%B1%E5%8C%97%E9%9B%BB%E5%8A%9B-%E3%82%88%E3%82%8A%E3%81%9D%E3%81%86%EF%BD%85%E3%81%AD%E3%81%A3%E3%81%A8/id1420949327?l=en-US
- https://jvn.jp/en/jp/JVN93985674/
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.