PT-2014-4649 · Oleumtech · Oleumtech Wio Dh2 Wireless Gateway+2
Published
2014-07-24
·
Updated
2025-10-06
·
CVE-2014-2361
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
OleumTech WIO DH2 Wireless Gateway and Sensor Wireless I/O Modules
Description
The issue allows physically proximate attackers to spoof communication by obtaining the site security key after using direct hardware access or manual-setup mode, as no authentication is required for reading this key when BreeZ is used.
Recommendations
For OleumTech WIO DH2 Wireless Gateway and Sensor Wireless I/O Modules, consider implementing authentication for reading the site security key when BreeZ is used to prevent unauthorized access. As a temporary workaround, restrict physical access to the devices to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Breez
Oleumtech Wio Dh2 Wireless Gateway
Sensor Wireless I/O Modules