CVE-2026-75553: Use of hard-coded cryptographic key in Tohoku Electric Power Company, Incorporated Tohoku Electric Power "Yorisou e Net" Android App
Smartphone application Tohoku Electric Power "Yorisou e Net" uses a hard-coded cryptographic key, which may allow an attacker to retrieve a hard-coded cryptographic key from the affected product.
AI Analysis
Technical Summary
CVE-2026-75553 identifies a vulnerability in the Tohoku Electric Power "Yorisou e Net" Android application where a cryptographic key is hard-coded within the app. This allows an attacker with access to the app binary to retrieve the key, potentially weakening cryptographic protections. The vulnerability affects all versions from 0 up to but not including 2.8.0. The CVSS 3.0 base score is 2.4, reflecting low impact with only confidentiality affected and no integrity or availability impact.
Potential Impact
The vulnerability may allow an attacker to obtain a hard-coded cryptographic key from the affected app, potentially compromising confidentiality of data protected by that key. There is no impact on integrity or availability. The low CVSS score indicates limited risk.
Mitigation Recommendations
No vendor advisory or patch information is provided. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, users should be cautious about the confidentiality of data protected by the app's cryptography.
CVE-2026-75553: Use of hard-coded cryptographic key in Tohoku Electric Power Company, Incorporated Tohoku Electric Power "Yorisou e Net" Android App
Description
Smartphone application Tohoku Electric Power "Yorisou e Net" uses a hard-coded cryptographic key, which may allow an attacker to retrieve a hard-coded cryptographic key from the affected product.
CVSS v3.0
Score 2.4low
Affected software
Tohoku Electric Power Company, Incorporated
Tohoku Electric Power "Yorisou e Net" Android App
Tohoku Electric Power Company, Incorporated
Tohoku Electric Power "Yorisou e Net" iOS App
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-75553 identifies a vulnerability in the Tohoku Electric Power "Yorisou e Net" Android application where a cryptographic key is hard-coded within the app. This allows an attacker with access to the app binary to retrieve the key, potentially weakening cryptographic protections. The vulnerability affects all versions from 0 up to but not including 2.8.0. The CVSS 3.0 base score is 2.4, reflecting low impact with only confidentiality affected and no integrity or availability impact.
Potential Impact
The vulnerability may allow an attacker to obtain a hard-coded cryptographic key from the affected app, potentially compromising confidentiality of data protected by that key. There is no impact on integrity or availability. The low CVSS score indicates limited risk.
Mitigation Recommendations
No vendor advisory or patch information is provided. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, users should be cautious about the confidentiality of data protected by the app's cryptography.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- jpcert
- Date Reserved
- 2026-08-24T07:04:44.688Z
- Cvss Version
- 3.0
- State
- PUBLISHED
Threat ID: 6ab67ba2f7a7c54106d708fc
Added to database: 09/25/2026, 13:48:18 UTC
Last enriched: 09/25/2026, 14:02:45 UTC
Last updated: 09/26/2026, 02:45:35 UTC
Views: 17
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.