PT-2023-29451 · Mr-Gm3+1 · Mr-Gm3+1

Goroh_Kun

+1

·

Published

2023-10-11

·

Updated

2023-10-31

·

CVE-2023-45194

CVSS v3.1

4.3

Medium

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions MR-GM2 firmware versions 3.00.03 and earlier MR-GM3 (-D/-K/-S/-DK/-DKS/-M/-W) firmware versions 1.03.45 and earlier
Description The issue allows a network-adjacent unauthenticated attacker to intercept wireless LAN communication when the affected product performs the communication without changing the pre-shared key from the factory-default configuration. This occurs due to the use of default credentials vulnerability in the firmware.
Recommendations For MR-GM2 firmware versions 3.00.03 and earlier, update the firmware to a version later than 3.00.03. For MR-GM3 (-D/-K/-S/-DK/-DKS/-M/-W) firmware versions 1.03.45 and earlier, update the firmware to a version later than 1.03.45. As a temporary workaround, consider changing the pre-shared key from the factory-default configuration to prevent interception of wireless LAN communication.

Fix

Using Hardcoded Credentials

Weakness Enumeration

Related Identifiers

CVE-2023-45194

Affected Products

Mr-Gm2
Mr-Gm3