PT-2023-2619 · Nexx · Nexx Garage Door Controller+2

CVE-2023-1748

·

Publicado

2023-04-04

·

Atualizado

2023-04-12

CVSS v2.0

10

Crítica

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Nexx Garage Door Controller versions NXG-100B, NXG-200 Nexx Smart Plug version NXPG-100W Nexx Smart Alarm version NXAL-100
Description The issue is related to the use of hard-coded credentials in the firmware of Nexx Smart Home devices. This could allow an attacker to gain unauthenticated access to the MQ Telemetry Server (MQTT) server, enabling them to remotely control garage doors or smart plugs for any customer.
Recommendations For Nexx Garage Door Controller versions NXG-100B, NXG-200, update the firmware to remove hard-coded credentials. For Nexx Smart Plug version NXPG-100W, update the firmware to remove hard-coded credentials. For Nexx Smart Alarm version NXAL-100, update the firmware to remove hard-coded credentials.

Correção

Using Hardcoded Credentials

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-02459
CVE-2023-1748

Produtos afetados

Nexx Garage Door Controller
Nexx Smart Alarm
Nexx Smart Plug