PT-2021-24115 · Wokka Lokka · Wokka Lokka Q50
Published
2021-12-01
·
Updated
2022-07-12
·
CVE-2021-44480
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
Wokka Lokka Q50 devices through 2021-11-30
Description:
The issue allows remote attackers who know the SIM phone number and password to listen to a device's surroundings via a callback in an SMS command. This is possible due to default passwords such as
123456 and 523681.Recommendations:
For Wokka Lokka Q50 devices through 2021-11-30, change the default passwords
123456 and 523681 to secure ones to prevent unauthorized access. As a temporary workaround, consider restricting access to SMS commands until a more secure configuration can be implemented.Fix
Cleartext Transmission of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Wokka Lokka Q50