V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2023-1748
CVE
Critical

The listed versions of Nexx Smart Home devices use hard-coded credentials. An attacker with unauthenticated access to the Nexx Home mobile …

CVSS
10.0
Critical
EPSS
0.01
p52
Published
2023-01-01
Updated
2023-01-01
Description

The listed versions of Nexx Smart Home devices use hard-coded credentials. An attacker with unauthenticated access to the Nexx Home mobile application or the affected firmware could view the credentials and access the MQ Telemetry Server (MQTT) server and the ability to remotely control garage doors or smart plugs for any customer.

Tags · CWE
Pre-auth
CWE-798
CAPEC-70
CAPEC-191
Affected products
Nxal-100_firmwareNxg-100b_firmwareNxg-200_firmwareNxpg-100w_firmware
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Timeline
2023-01-01
Published
2023-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: N
None (N)
Scope
S: C
Changed (C)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: H
High (H)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.008 · p52
Known exploited (KEV)
No
MITRE ATT&CK
Inferred via CAPEC
└ via CAPEC-70 · CWE-798
└ via CAPEC-191 · CWE-798
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected products
ProductVendorStatus
nxal-100_firmware*Tracked
nxg-100b_firmware*Tracked
nxg-200_firmware*Tracked
nxpg-100w_firmware*Tracked
Source databases
CVE
Related vulnerabilities