PT-2023-27945 · Kloudq Technologies Limited · Tor Equip+1

Published

2023-11-15

·

Updated

2023-12-01

·

CVE-2023-41442

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Kloudq Technologies Limited Tor Equip version 1.0 Kloudq Technologies Limited Tor Loco Mini versions 1.0 through 3.1
Description The issue allows a remote attacker to execute arbitrary code via a crafted request to the "MQTT component".
Recommendations For Kloudq Technologies Limited Tor Equip version 1.0, consider disabling the MQTT component until a patch is available. For Kloudq Technologies Limited Tor Loco Mini versions 1.0 through 3.1, restrict access to the MQTT component to minimize the risk of exploitation.

Exploit

Fix

Improper Authentication

Weakness Enumeration

Related Identifiers

CVE-2023-41442

Affected Products

Tor Equip
Tor Loco Mini