CRITICAL · 9.3

CVE-2023-1748

The listed versions of Nexx Smart Home devices use hard-coded credentials. An attacker with unauthenticated access to the Nexx Home mobile application or the affected firmware could view the credentia...

Vulnerability Description

The listed versions of Nexx Smart Home devices use hard-coded credentials. An attacker with unauthenticated access to the Nexx Home mobile application or the affected firmware could view the credentials and access the MQ Telemetry Server (MQTT) server and the ability to remotely control garage doors or smart plugs for any customer.

CVSS Score

9.3

CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
LOW

Affected Products

VendorProductVersions
GetnexxNxal-100 Firmware<= nxal100v-p1-9-1
GetnexxNxal-100-
GetnexxNxg-100B Firmware<= nxg100bv-p3-4-1
GetnexxNxg-100B-
GetnexxNxpg-100W Firmware<= nxpg100cv4-0-0
GetnexxNxpg-100W-
GetnexxNxg-200 Firmware<= nxg200v-p3-4-1
GetnexxNxg-200-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2023-1748?

CVE-2023-1748 is a vulnerability with a CVSS score of 9.3 (CRITICAL). The listed versions of Nexx Smart Home devices use hard-coded credentials. An attacker with unauthenticated access to the Nexx Home mobile application or the affected firmware could view the credentia...

How severe is CVE-2023-1748?

CVE-2023-1748 has been rated CRITICAL with a CVSS base score of 9.3/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2023-1748?

Check the references section above for vendor advisories and patch information. Affected products include: Getnexx Nxal-100 Firmware, Getnexx Nxal-100, Getnexx Nxg-100B Firmware, Getnexx Nxg-100B, Getnexx Nxpg-100W Firmware.