Elemental Path's CogniToys Dino smart toys through firmware version 0.0.794 share a fixed small pool of hardcoded keys, allowing a remote malicious user to use a different Dino device to decrypt VoIP traffic between a child's Dino and remote server.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
cognitoys stemosaur_firmware |