Vulnerability Description
Meross Smart Wi-Fi 2 Way Wall Switch (MSS550X), on its 3.1.3 version and before, creates an open Wi-Fi Access Point without the required security measures in its initial setup. This could allow a remote attacker to obtain the Wi-Fi SSID as well as the password configured by the user from Meross app via Http/JSON plain request.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Meross | Mss550X Firmware | <= 3.1.3 |
| Meross | Mss550X | - |
Related Weaknesses (CWE)
References
- https://www.incibe.es/en/incibe-cert/notices/aviso/meross-mss550x-missing-encryp
- https://www.incibe.es/en/incibe-cert/notices/aviso/meross-mss550x-missing-encryp
FAQ
What is CVE-2021-3774?
CVE-2021-3774 is a vulnerability with a CVSS score of 7.4 (HIGH). Meross Smart Wi-Fi 2 Way Wall Switch (MSS550X), on its 3.1.3 version and before, creates an open Wi-Fi Access Point without the required security measures in its initial setup. This could allow a remo...
How severe is CVE-2021-3774?
CVE-2021-3774 has been rated HIGH with a CVSS base score of 7.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-3774?
Check the references section above for vendor advisories and patch information. Affected products include: Meross Mss550X Firmware, Meross Mss550X.