HomeSecurityVulnerability detected in Thinkware Cloud APK

Vulnerability detected in Thinkware Cloud APK

A serious vulnerability was recently identified in version 4.3.46 of the Thinkware Cloud APK , which is used in Thinkware's cloud dashcam services

Vulnerability detected in Thinkware Cloud APK

The vulnerability, identified by CVE-2024-53614, can allow malicious users to gain access to sensitive data and execute commands with elevated privileges, jeopardizing the privacy and security of the system.

See also: SharePoint RCE vulnerability allows domain compromise

The issue stems from the use of an embedded cryptographic key within the application, a weakness classified as CWE-321: Use of Embedded Cryptographic Key. According to specialist analyst George Chen, this vulnerability opens the door to unauthorized access to encrypted data.

A possible attack scenario includes the Man-in-the-Middle (MitM) method, through which an attacker can intercept encrypted connection data, obtaining access credentials to the Thinkware Cloud.

Read more: GitHub CLI RCE vulnerability allows execution of malicious commands

This could lead to serious privacy breaches, as sensitive audiovisual material from dashcams may leak, putting users at risk such as identity theft or extortion.

The vulnerability has been rated with a CVSS score of 6.5 (moderate severity), although the potential impacts could be much larger. Thinkware was notified of the issue on November 12, 2024 and is already working on its resolution.

Vulnerability detected in Thinkware Cloud APK

See also: Vulnerability in Atlassian Sourcetree allows code execution

In the meantime, users are urged to take preventive measures: avoid using insecure Wi‑Fi networks, monitor account activities for any suspicious actions, and temporarily disable cloud functions until the relevant update is released.

Source: cybersecuritynews

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS