Cryptographic Key Exposure in Tohoku Electric Power Mobile Application
CVE-2026-75553
2.4LOW
Key Information:
- Status
- Vendor
- CVE Published:
- 25 September 2026
What is CVE-2026-75553?
The Tohoku Electric Power app 'Yorisou e Net' contains a vulnerability due to a hard-coded cryptographic key. This exposure may permit malicious actors to extract sensitive cryptographic keys from the application, potentially jeopardizing user data and system integrity. Users should be aware of this risk and consider reviewing the app for updates or security audits.
Affected Version(s)
Tohoku Electric Power "Yorisou e Net" Android App 0 < 2.8.0
Tohoku Electric Power "Yorisou e Net" iOS App 0 < 2.8.0
References
CVSS V4
Score:
2.4
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Physical
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
CVSS V3.0
Score:
2.4
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
