CVE-2024-9991

Severity CVSS v4.0:
HIGH
Type:
CWE-312 Cleartext Storage of Sensitive Information
Publication date:
25/10/2024
Last modified:
15/04/2026

Description

This vulnerability exists in Philips lighting devices due to storage of Wi-Fi credentials in plain text within the device firmware. An attacker with physical access could exploit this by extracting the firmware and analyzing the binary data to obtain the plaintext Wi-Fi credentials stored on the vulnerable device.<br /> <br /> Successful exploitation of this vulnerability could allow an attacker to gain unauthorized access to the Wi-Fi network to which vulnerable device is connected.