Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5mh7-cqvw-mcp7

Опубликовано: 28 авг. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 2.4

Описание

Meitrack T366G-L GPS Tracker devices contain an SPI flash chip (Winbond 25Q64JVSIQ) that is accessible without authentication or tamper protection. An attacker with physical access to the device can use a standard SPI programmer to extract the firmware using flashrom. This results in exposure of sensitive configuration data such as APN credentials, backend server information, and network parameter

Meitrack T366G-L GPS Tracker devices contain an SPI flash chip (Winbond 25Q64JVSIQ) that is accessible without authentication or tamper protection. An attacker with physical access to the device can use a standard SPI programmer to extract the firmware using flashrom. This results in exposure of sensitive configuration data such as APN credentials, backend server information, and network parameter

EPSS

Процентиль: 4%
0.00018
Низкий

2.4 Low

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 2.4
nvd
5 месяцев назад

Meitrack T366G-L GPS Tracker devices contain an SPI flash chip (Winbond 25Q64JVSIQ) that is accessible without authentication or tamper protection. An attacker with physical access to the device can use a standard SPI programmer to extract the firmware using flashrom. This results in exposure of sensitive configuration data such as APN credentials, backend server information, and network parameter

EPSS

Процентиль: 4%
0.00018
Низкий

2.4 Low

CVSS3

Дефекты

CWE-200