Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-p792-3c6f-m4p5

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

Meross Smart Wi-Fi 2 Way Wall Switch (MSS550X), on its 3.1.3 version and before, creates an open Wi-Fi Access Point without the required security measures in its initial setup. This could allow a remote attacker to obtain the Wi-Fi SSID as well as the password configured by the user from Meross app via Http/JSON plain request.

Meross Smart Wi-Fi 2 Way Wall Switch (MSS550X), on its 3.1.3 version and before, creates an open Wi-Fi Access Point without the required security measures in its initial setup. This could allow a remote attacker to obtain the Wi-Fi SSID as well as the password configured by the user from Meross app via Http/JSON plain request.

EPSS

Процентиль: 36%
0.00151
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-311
CWE-319

Связанные уязвимости

CVSS3: 7.4
nvd
больше 4 лет назад

Meross Smart Wi-Fi 2 Way Wall Switch (MSS550X), on its 3.1.3 version and before, creates an open Wi-Fi Access Point without the required security measures in its initial setup. This could allow a remote attacker to obtain the Wi-Fi SSID as well as the password configured by the user from Meross app via Http/JSON plain request.

EPSS

Процентиль: 36%
0.00151
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-311
CWE-319