---
id: CVE-2026-75553
title: >-
  Smartphone application Tohoku Electric Power "Yorisou e Net" uses a hard-coded
  cryptographic key, which may allow an attacker to retrieve a hard-coded
  cryptographic key from the affected product.
summary: >-
  Smartphone application Tohoku Electric Power "Yorisou e Net" uses a hard-coded
  cryptographic key, which may allow an attacker to retrieve a hard-coded
  cryptographic key from the affected product.
severity: low
cvss: 2.4
cvssVector: 'CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-321
vendor: 'Tohoku Electric Power Company, Incorporated'
product: Tohoku Electric Power "Yorisou e Net" Android App
affected:
  - tohoku_electric_power_yorisou_e_net_android_app < 2.8.0
  - tohoku_electric_power_yorisou_e_net_ios_app < 2.8.0
published: '2026-09-25'
updated: '2026-09-25'
sourceUpdated: '2026-09-25T14:17:18.930'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-75553'
references:
  - url: >-
      https://apps.apple.com/jp/app/%E6%9D%B1%E5%8C%97%E9%9B%BB%E5%8A%9B-%E3%82%88%E3%82%8A%E3%81%9D%E3%81%86%EF%BD%85%E3%81%AD%E3%81%A3%E3%81%A8/id1420949327?l=en-US
    label: vultures@jpcert.or.jp
  - url: 'https://jvn.jp/en/jp/JVN93985674/'
    label: vultures@jpcert.or.jp
  - url: 'https://play.google.com/store/apps/details?id=jp.co.tohokuepco.enet&hl=ja'
    label: vultures@jpcert.or.jp
tags:
  - nvd
  - cve.org
epss: 0.00142
epssPercentile: 0.02842
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-25T13:32:10.369668Z'
ingestedAt: '2026-09-25T07:01:12.115Z'
---

## Overview

Smartphone application Tohoku Electric Power "Yorisou e Net" uses a hard-coded cryptographic key, which may allow an attacker to retrieve a hard-coded cryptographic key from the affected product.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
