Описание
Use of Hard-coded Credentials in temi Robox OS prior to 120, temi Android app up to 1.3.7931 allows remote attackers to listen in on any ongoing calls between temi robots and their users if they can brute-force/guess a six-digit value via unspecified vectors.
Ссылки
- ExploitThird Party Advisory
- Vendor Advisory
- ExploitThird Party Advisory
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 1.3.3 (включая) до 1.3.7931 (включая)
cpe:2.3:a:robotemi:temi:*:*:*:*:*:android:*:*
EPSS
Процентиль: 70%
0.00655
Низкий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-798
Связанные уязвимости
CVSS3: 7.5
github
больше 3 лет назад
The Temi application 1.3.3 through 1.3.7931 for Android has hard-coded credentials.
EPSS
Процентиль: 70%
0.00655
Низкий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-798