The listed versions of Nexx Smart Home devices use hard-coded credentials. An attacker with unauthenticated access to the Nexx Home mobile application or the affected firmware could view the credentials and access the MQ Telemetry Server (MQTT) server and the ability to remotely control garage doors or smart plugs for any customer.
References
Link | Resource |
---|---|
https://www.cisa.gov/news-events/ics-advisories/icsa-23-094-01 | Third Party Advisory US Government Resource |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: icscert
Published: 2023-04-04T16:56:27.851Z
Updated: 2023-04-04T16:56:27.851Z
Reserved: 2023-03-30T20:01:18.851Z
Link: CVE-2023-1748
JSON object: View
NVD Information
Status : Modified
Published: 2023-04-04T17:15:07.060
Modified: 2023-11-07T04:04:48.833
Link: CVE-2023-1748
JSON object: View
Redhat Information
No data.
CWE