PT-2019-14042 · Lierda+1 · Lierda Grill Temperature Monitor+1

Tim Tepatti

·

Published

2019-08-26

·

Updated

2020-09-24

·

CVE-2019-15304

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions Lierda Grill Temperature Monitor version V1.00 50006 ProGrade Grill Temperature Monitor (affected versions not specified)
Description The issue concerns a default password set to admin for the admin account, allowing potential Denial of Service or Information Disclosure attacks via an undocumented access-point configuration page on the device. The accompanying wifi thermometer app requires excessive permissions, including Fine GPS location, camera, app lists, Serial number, and IMEI. Additionally, the app connects to several China-based URLs, including Alibaba cloud computing. There is also a "backdoor" login access for admin purposes.
Recommendations For Lierda Grill Temperature Monitor version V1.00 50006, consider changing the default admin password to a strong, unique password to prevent unauthorized access. For ProGrade Grill Temperature Monitor, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-15304

Affected Products

Lierda Grill Temperature Monitor
Prograde Grill Temperature Monitor