PT-2020-12495 · Thinx · Thinx-Device-Api

Suculent

·

Published

2020-04-30

·

Updated

2022-10-29

·

CVE-2020-11015

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions thinx-device-api IoT Device Management Server versions prior to 2.5.0
Description A vulnerability has been disclosed in the thinx-device-api IoT Device Management Server, where the device MAC address can be spoofed. This allows initial registration requests without a UDID and a spoofed MAC address to create a new UDID with the same MAC address. The full impact of this issue needs to be reviewed further. It applies to all users, mostly those using ESP8266/ESP32 devices.
Recommendations For versions prior to 2.5.0, update to firmware version 2.5.0 to resolve the issue. As a temporary workaround, consider restricting access to the initial registration request endpoint to minimize the risk of exploitation. Avoid using spoofed MAC addresses in registration requests until the issue is resolved.

Fix

Authentication Bypass by Spoofing

Weakness Enumeration

Related Identifiers

CVE-2020-11015
GHSA-5X54-39XQ-CWVC

Affected Products

Thinx-Device-Api