The listed versions of Nexx Smart Home devices use hard-coded credentials. An attacker with unauthenticated access to the Nexx Home mobile application or the affected firmware could view the credentials and access the MQ Telemetry Server (MQTT) server and the ability to remotely control garage doors or smart plugs for any customer.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: icscert
Published: 2023-04-04T16:56:27.851Z
Updated: 2024-08-02T05:57:25.127Z
Reserved: 2023-03-30T20:01:18.851Z
Link: CVE-2023-1748
Vulnrichment
No data.
NVD
Status : Modified
Published: 2023-04-04T17:15:07.060
Modified: 2024-11-21T07:39:49.367
Link: CVE-2023-1748
Redhat
No data.