PT-2023-2619 · Nexx · Nexx Garage Door Controller+2
CVE-2023-1748
·
Publicado
2023-04-04
·
Atualizado
2023-04-12
CVSS v2.0
10
Crítica
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Nexx Garage Door Controller versions NXG-100B, NXG-200
Nexx Smart Plug version NXPG-100W
Nexx Smart Alarm version NXAL-100
Description
The issue is related to the use of hard-coded credentials in the firmware of Nexx Smart Home devices. This could allow an attacker to gain unauthenticated access to the MQ Telemetry Server (MQTT) server, enabling them to remotely control garage doors or smart plugs for any customer.
Recommendations
For Nexx Garage Door Controller versions NXG-100B, NXG-200, update the firmware to remove hard-coded credentials.
For Nexx Smart Plug version NXPG-100W, update the firmware to remove hard-coded credentials.
For Nexx Smart Alarm version NXAL-100, update the firmware to remove hard-coded credentials.
Correção
Using Hardcoded Credentials
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Nexx Garage Door Controller
Nexx Smart Alarm
Nexx Smart Plug