Vulnerability Description
The Chuango 433 MHz burglar-alarm product line uses static codes in the RF remote control, allowing an attacker to arm, disarm, or trigger the alarm remotely via replay attacks, as demonstrated by Chuango branded products, and non-Chuango branded products such as the Eminent EM8617 OV2 Wifi Alarm System.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Chuango | Wifi Alarm System Firmware | - |
| Chuango | Wifi Alarm System | - |
| Chuango | Wifi\/Cellular Smart Home System H4 Plus Firmware | - |
| Chuango | Wifi\/Cellular Smart Home System H4 Plus | - |
| Chuango | Awv Plus Wifi Alarm System Firmware | - |
| Chuango | Awv Plus Wifi Alarm System | - |
| Chuango | G5W 3G Firmware | - |
| Chuango | G5W 3G | - |
| Chuango | G5 Plus Gsm\/Sms\/Rfid Touch Alarm System Firmware | - |
| Chuango | G5 Plus Gsm\/Sms\/Rfid Touch Alarm System | - |
| Chuango | G3 Gsm\/Sms Alarm System Firmware | - |
| Chuango | G3 Gsm\/Sms Alarm System | - |
| Chuango | B11 Dual-Network Alarm System Firmware | - |
| Chuango | B11 Dual-Network Alarm System | - |
| Chuango | A8 Pstn Alarm System Firmware | - |
| Chuango | A8 Pstn Alarm System | - |
| Chuango | A11 Pstn\/Lcd\/Rfid Touch Alarm System Firmware | - |
| Chuango | A11 Pstn\/Lcd\/Rfid Touch Alarm System | - |
| Chuango | Cg-105S On-Site Alarm System Firmware | - |
| Chuango | Cg-105S On-Site Alarm System | - |
Related Weaknesses (CWE)
References
- https://github.com/RiieCco/write-ups/tree/master/CVE-2019-9659Third Party Advisory
- https://github.com/RiieCco/write-ups/tree/master/CVE-2019-9659Third Party Advisory
FAQ
What is CVE-2019-9659?
CVE-2019-9659 is a vulnerability with a CVSS score of 9.1 (CRITICAL). The Chuango 433 MHz burglar-alarm product line uses static codes in the RF remote control, allowing an attacker to arm, disarm, or trigger the alarm remotely via replay attacks, as demonstrated by Chu...
How severe is CVE-2019-9659?
CVE-2019-9659 has been rated CRITICAL with a CVSS base score of 9.1/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2019-9659?
Check the references section above for vendor advisories and patch information. Affected products include: Chuango Wifi Alarm System Firmware, Chuango Wifi Alarm System, Chuango Wifi\/Cellular Smart Home System H4 Plus Firmware, Chuango Wifi\/Cellular Smart Home System H4 Plus, Chuango Awv Plus Wifi Alarm System Firmware.