Getnexx
Getnexx Nxg-100b Firmware: vulnerabilidades y CVE
Getnexx Nxg-100b Firmware tiene 5 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE5
Últimos 12 meses0
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-1752 | Media (4.3) | 0.52% | — | 4 abr 2023 | The listed versions of Nexx Smart Home devices could allow any user to register an already registered alarm or associated device with only the device’s MAC address. |
| CVE-2023-1751 | Media (5.3) | 0.59% | — | 4 abr 2023 | The listed versions of Nexx Smart Home devices use a WebSocket server that does not validate if the bearer token in the Authorization header belongs to the device attempting to associate. This could allow any authorized… |
| CVE-2023-1750 | Alta (7.1) | 0.48% | — | 4 abr 2023 | The listed versions of Nexx Smart Home devices lack proper access control when executing actions. An attacker with a valid NexxHome deviceId could retrieve device history, set device settings, and retrieve device… |
| CVE-2023-1749 | Media (6.5) | 0.50% | — | 4 abr 2023 | The listed versions of Nexx Smart Home devices lack proper access control when executing actions. An attacker with a valid NexxHome deviceId could send API requests that the affected devices would execute. |
| CVE-2023-1748 | Crítica (10) | 0.83% | — | 4 abr 2023 | The listed versions of Nexx Smart Home devices use hard-coded credentials. An attacker with unauthenticated access to the Nexx Home mobile application or the affected firmware could view the credentials and access the… |