PT-2024-13863 · Flient · Flient Smart Door Lock

Published

2024-01-11

·

Updated

2024-09-03

·

CVE-2023-50124

CVSS v3.1

6.8

Medium

VectorAV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Flient Smart Door Lock version 1.0
Description The issue is related to the use of default credentials on a debug interface, combined with certain design choices, allowing an attacker to unlock the Flient Smart Door Lock by replacing the fingerprint stored on the scanner.
Recommendations For Flient Smart Door Lock version 1.0, consider changing the default credentials on the debug interface to prevent unauthorized access. As a temporary workaround, restrict access to the debug interface until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Using Hardcoded Credentials

Weakness Enumeration

Related Identifiers

CVE-2023-50124

Affected Products

Flient Smart Door Lock