PT-2023-29451 · Mr-Gm3+1 · Mr-Gm3+1

Goroh_Kun

+1

·

Publicado

2023-10-11

·

Atualizado

2023-10-31

·

CVE-2023-45194

CVSS v3.1

4.3

Média

VetorAV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions MR-GM2 firmware versions 3.00.03 and earlier MR-GM3 (-D/-K/-S/-DK/-DKS/-M/-W) firmware versions 1.03.45 and earlier
Description The issue allows a network-adjacent unauthenticated attacker to intercept wireless LAN communication when the affected product performs the communication without changing the pre-shared key from the factory-default configuration. This occurs due to the use of default credentials vulnerability in the firmware.
Recommendations For MR-GM2 firmware versions 3.00.03 and earlier, update the firmware to a version later than 3.00.03. For MR-GM3 (-D/-K/-S/-DK/-DKS/-M/-W) firmware versions 1.03.45 and earlier, update the firmware to a version later than 1.03.45. As a temporary workaround, consider changing the pre-shared key from the factory-default configuration to prevent interception of wireless LAN communication.

Correção

Using Hardcoded Credentials

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-45194

Produtos afetados

Mr-Gm2
Mr-Gm3