PT-2019-19783 · Chuango+1 · Chuango+1

Riccardo Ten Cate

·

Published

2019-03-11

·

Updated

2021-07-21

·

CVE-2019-9659

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:P
Name of the Vulnerable Software and Affected Versions Chuango 433 MHz burglar-alarm product line (affected versions not specified) Eminent EM8617 OV2 Wifi Alarm System (affected versions not specified)
Description The issue concerns the use of static codes in the RF remote control of the affected products, allowing an attacker to perform unauthorized actions such as arming, disarming, or triggering the alarm remotely through replay attacks.
Recommendations For the Chuango 433 MHz burglar-alarm product line, consider implementing a code-hopping or rolling code mechanism to prevent replay attacks until a patch is available. For the Eminent EM8617 OV2 Wifi Alarm System, restrict access to the alarm system's remote control functionality to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-9659

Affected Products

Chuango
Eminent Em8617 Ov2 Wifi Alarm System