Описание
Origin Validation Error in temi Robox OS prior to 120, temi Android app up to 1.3.7931 allows remote attackers to access the REST API and MQTT broker used by the temi and send it custom data/requests via unspecified vectors.
Ссылки
- ExploitThird Party Advisory
- Vendor Advisory
- ExploitThird Party Advisory
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.3.7931 (исключая)
Одновременно
cpe:2.3:o:robotemi:temi_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:robotemi:temi:-:*:*:*:*:*:*:*
EPSS
Процентиль: 35%
0.00145
Низкий
6.5 Medium
CVSS3
4.3 Medium
CVSS2
Дефекты
CWE-346
Связанные уязвимости
CVSS3: 6.5
github
около 3 лет назад
Temi firmware 20190419.165201 does not properly verify that the source of data or communication is valid, aka an Origin Validation Error.
EPSS
Процентиль: 35%
0.00145
Низкий
6.5 Medium
CVSS3
4.3 Medium
CVSS2
Дефекты
CWE-346