PT-2019-12964 · Shenzhen Jisiwei · Shenzhen Jisiwei I3 Robot Vacuum Cleaner App

Published

2019-07-19

·

Updated

2020-08-24

·

CVE-2019-12820

CVSS v3.1

5.6

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Shenzhen Jisiwei i3 robot vacuum cleaner app version 2.0
Description A security issue was discovered in the app, where actions like changing passwords and communicating personal information with the server use unencrypted HTTP. For instance, login requests to a Jisiwei account are sent in cleartext. This affects both Android and iOS versions of the app. An attacker could exploit this using a Man-in-the-Middle (MiTM) attack on the local network to obtain login credentials, granting full access to the robot vacuum cleaner.
Recommendations For app version 2.0, consider disabling the login functionality until a secure version of the app is available, and avoid using the app on untrusted networks to minimize the risk of exploitation.

Exploit

Fix

Cleartext Transmission of Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-12820

Affected Products

Shenzhen Jisiwei I3 Robot Vacuum Cleaner App