PT-2018-13046 · Mystrom · Mystrom Wifi Button Plus+6

Almeroth

+1

·

Published

2018-08-30

·

Updated

2019-10-03

·

CVE-2018-15480

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions myStrom WiFi Switch V1 versions prior to 2.66 myStrom WiFi Switch V2 versions prior to 3.80 myStrom WiFi Switch EU versions prior to 3.80 myStrom WiFi Bulb versions prior to 2.58 myStrom WiFi LED Strip versions prior to 3.80 myStrom WiFi Button versions prior to 2.73 myStrom WiFi Button Plus versions prior to 2.73
Description An issue was discovered in the cloud API, where a hidden parameter allowed an authenticated user to reconfigure the server URL for a device registered to their account. This, in combination with an insecure device registration, enabled an attacker to reconfigure a maliciously registered device to their own rogue replica of the API and issue commands, including firmware updates.
Recommendations For myStrom WiFi Switch V1 versions prior to 2.66, update to version 2.66 or later. For myStrom WiFi Switch V2 versions prior to 3.80, update to version 3.80 or later. For myStrom WiFi Switch EU versions prior to 3.80, update to version 3.80 or later. For myStrom WiFi Bulb versions prior to 2.58, update to version 2.58 or later. For myStrom WiFi LED Strip versions prior to 3.80, update to version 3.80 or later. For myStrom WiFi Button versions prior to 2.73, update to version 2.73 or later. For myStrom WiFi Button Plus versions prior to 2.73, update to version 2.73 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2018-15480

Affected Products

Mystrom Wifi Bulb
Mystrom Wifi Button
Mystrom Wifi Button Plus
Mystrom Wifi Led Strip
Mystrom Wifi Switch Eu
Mystrom Wifi Switch V1
Mystrom Wifi Switch V2