« Back to list

CVE-2023-1748

Status: ModifiedCritical (10)—

The listed versions of Nexx Smart Home devices use hard-coded credentials. An attacker with unauthenticated access to the Nexx Home mobile application or the affected firmware could view the credentials and access the MQ Telemetry Server (MQTT) server and the ability to remotely control garage doors or smart plugs for any customer.

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

Affected technologies (4)

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2023-1748",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2023-1748",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-01-16T20:55:55.953511Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "ics-cert@hq.dhs.gov",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 9.3,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "LOW",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 4.7,
        "exploitabilityScore": 3.9
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 10,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "ics-cert@hq.dhs.gov",
      "affectedData": [
        {
          "vendor": "Nexx",
          "product": "Smart Alarm NXAL-100",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "versionType": "custom",
              "lessThanOrEqual": "nxal100v-p1-9-1"
            }
          ]
        },
        {
          "vendor": "Nexx",
          "product": "Smart Plug NXPG-100W",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "versionType": "custom",
              "lessThanOrEqual": "nxpg100cv4-0-0"
            }
          ]
        },
        {
          "vendor": "Nexx",
          "product": "Garage Door Controller NXG-100B, NXG-200",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "versionType": "custom",
              "lessThanOrEqual": "nxg200v-p3-4-1"
            }
          ]
        }
      ]
    }
  ],
  "published": "2023-04-04T17:15:07.060",
  "references": [
    {
      "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-23-094-01",
      "tags": [
        "Third Party Advisory",
        "US Government Resource"
      ],
      "source": "ics-cert@hq.dhs.gov"
    },
    {
      "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-23-094-01",
      "tags": [
        "Third Party Advisory",
        "US Government Resource"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-798"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The listed versions of Nexx Smart Home devices use hard-coded credentials. An attacker with unauthenticated access to the Nexx Home mobile application or the affected firmware could view the credentials and access the MQ Telemetry Server (MQTT) server and the ability to remotely control garage doors or smart plugs for any customer."
    }
  ],
  "lastModified": "2026-06-17T05:28:40.400",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:getnexx:nxal-100_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "ECEB2E75-CBB4-4698-8362-E299B360D230",
              "versionEndIncluding": "nxal100v-p1-9-1"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:getnexx:nxal-100:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "A105A0A9-453D-4FEC-A892-90DF700AF48F"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:getnexx:nxg-100b_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CFED44C1-D08F-485F-9613-2FF354646544",
              "versionEndIncluding": "nxg100bv-p3-4-1"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:getnexx:nxg-100b:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "19767CB6-01EC-4D9A-B879-622D97659C41"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:getnexx:nxpg-100w_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "705949CF-FA4F-4D31-A125-897E4738FD60",
              "versionEndIncluding": "nxpg100cv4-0-0"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:getnexx:nxpg-100w:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "BABBFCE0-C690-4867-9416-5C9E453A6B1F"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:getnexx:nxg-200_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5D3856AF-F315-4D54-A415-23D870E57FDC",
              "versionEndIncluding": "nxg200v-p3-4-1"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:getnexx:nxg-200:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "E23E0481-74FD-4F0C-926C-D303DF9F9E68"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "ics-cert@hq.dhs.gov"
}