PT-2019-14042 · Lierda+1 · Lierda Grill Temperature Monitor+1

Tim Tepatti

·

Publicado

2019-08-26

·

Atualizado

2020-09-24

·

CVE-2019-15304

CVSS v3.1

9.1

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions Lierda Grill Temperature Monitor version V1.00 50006 ProGrade Grill Temperature Monitor (affected versions not specified)
Description The issue concerns a default password set to admin for the admin account, allowing potential Denial of Service or Information Disclosure attacks via an undocumented access-point configuration page on the device. The accompanying wifi thermometer app requires excessive permissions, including Fine GPS location, camera, app lists, Serial number, and IMEI. Additionally, the app connects to several China-based URLs, including Alibaba cloud computing. There is also a "backdoor" login access for admin purposes.
Recommendations For Lierda Grill Temperature Monitor version V1.00 50006, consider changing the default admin password to a strong, unique password to prevent unauthorized access. For ProGrade Grill Temperature Monitor, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-15304

Produtos afetados

Lierda Grill Temperature Monitor
Prograde Grill Temperature Monitor