PT-2019-12833 · Inateck · Inateck Wp1001
Published
2019-06-07
·
Updated
2020-08-24
·
CVE-2019-12505
CVSS v3.1
8.8
High
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Inateck WP1001 version 1.3C
Description
The issue allows for keystroke injection attacks due to unencrypted and unauthenticated data communication. This enables an attacker to send arbitrary keystrokes to a victim's computer system, potentially installing malware on an unattended target system. As a result, an attacker can remotely take control of the victim's computer that is operated with an affected receiver of this device.
Recommendations
For Inateck WP1001 version 1.3C, consider disabling the device until a patch or secure alternative is available to prevent keystroke injection attacks. Restrict access to sensitive systems and data when using the affected device to minimize the risk of exploitation.
Fix
Missing Authentication
Cleartext Transmission of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Inateck Wp1001