Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jj5g-444x-7r89

Опубликовано: 04 апр. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 10

Описание

The listed versions of Nexx Smart Home devices use hard-coded credentials. An attacker with unauthenticated access to the Nexx Home mobile application or the affected firmware could view the credentials and access the MQ Telemetry Server (MQTT) server and the ability to remotely control garage doors or smart plugs for any customer.

The listed versions of Nexx Smart Home devices use hard-coded credentials. An attacker with unauthenticated access to the Nexx Home mobile application or the affected firmware could view the credentials and access the MQ Telemetry Server (MQTT) server and the ability to remotely control garage doors or smart plugs for any customer.

EPSS

Процентиль: 31%
0.00119
Низкий

10 Critical

CVSS3

Дефекты

CWE-798

Связанные уязвимости

CVSS3: 9.3
nvd
почти 3 года назад

The listed versions of Nexx Smart Home devices use hard-coded credentials. An attacker with unauthenticated access to the Nexx Home mobile application or the affected firmware could view the credentials and access the MQ Telemetry Server (MQTT) server and the ability to remotely control garage doors or smart plugs for any customer.

CVSS3: 10
fstec
почти 3 года назад

Уязвимость микропрограммного обеспечения контроллеров Nexx Garage Door Controller (NXG-100B, NXG-200), Nexx Smart Plug (NXPG-100W), Nexx Smart Alarm (NXAL-100), связанная с использованием предустановленных учетных данных, позволяющая нарушителю получить неаутентифицированный доступ к серверу MQ Telemetry Server (MQTT)

EPSS

Процентиль: 31%
0.00119
Низкий

10 Critical

CVSS3

Дефекты

CWE-798