CVE-2023-1748
Status: ModifiedCritical (10)—
The listed versions of Nexx Smart Home devices use hard-coded credentials. An attacker with unauthenticated access to the Nexx Home mobile application or the affected firmware could view the credentials and access the MQ Telemetry Server (MQTT) server and the ability to remotely control garage doors or smart plugs for any customer.
CVSS
- Version: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
- Base score: 10
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 0.83%
- Percentile among all scored CVEs: 56
- Score date: 10/6/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (4)
CWEs
- CWE-798
References
Raw JSON (NVD)
Show
{
"id": "CVE-2023-1748",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2023-1748",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "yes"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2025-01-16T20:55:55.953511Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "ics-cert@hq.dhs.gov",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 9.3,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "LOW",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 4.7,
"exploitabilityScore": 3.9
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 10,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 6,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "ics-cert@hq.dhs.gov",
"affectedData": [
{
"vendor": "Nexx",
"product": "Smart Alarm NXAL-100",
"versions": [
{
"status": "affected",
"version": "0",
"versionType": "custom",
"lessThanOrEqual": "nxal100v-p1-9-1"
}
]
},
{
"vendor": "Nexx",
"product": "Smart Plug NXPG-100W",
"versions": [
{
"status": "affected",
"version": "0",
"versionType": "custom",
"lessThanOrEqual": "nxpg100cv4-0-0"
}
]
},
{
"vendor": "Nexx",
"product": "Garage Door Controller NXG-100B, NXG-200",
"versions": [
{
"status": "affected",
"version": "0",
"versionType": "custom",
"lessThanOrEqual": "nxg200v-p3-4-1"
}
]
}
]
}
],
"published": "2023-04-04T17:15:07.060",
"references": [
{
"url": "https://www.cisa.gov/news-events/ics-advisories/icsa-23-094-01",
"tags": [
"Third Party Advisory",
"US Government Resource"
],
"source": "ics-cert@hq.dhs.gov"
},
{
"url": "https://www.cisa.gov/news-events/ics-advisories/icsa-23-094-01",
"tags": [
"Third Party Advisory",
"US Government Resource"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-798"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The listed versions of Nexx Smart Home devices use hard-coded credentials. An attacker with unauthenticated access to the Nexx Home mobile application or the affected firmware could view the credentials and access the MQ Telemetry Server (MQTT) server and the ability to remotely control garage doors or smart plugs for any customer."
}
],
"lastModified": "2026-06-17T05:28:40.400",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:getnexx:nxal-100_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "ECEB2E75-CBB4-4698-8362-E299B360D230",
"versionEndIncluding": "nxal100v-p1-9-1"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:getnexx:nxal-100:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "A105A0A9-453D-4FEC-A892-90DF700AF48F"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:getnexx:nxg-100b_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CFED44C1-D08F-485F-9613-2FF354646544",
"versionEndIncluding": "nxg100bv-p3-4-1"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:getnexx:nxg-100b:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "19767CB6-01EC-4D9A-B879-622D97659C41"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:getnexx:nxpg-100w_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "705949CF-FA4F-4D31-A125-897E4738FD60",
"versionEndIncluding": "nxpg100cv4-0-0"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:getnexx:nxpg-100w:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "BABBFCE0-C690-4867-9416-5C9E453A6B1F"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:getnexx:nxg-200_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5D3856AF-F315-4D54-A415-23D870E57FDC",
"versionEndIncluding": "nxg200v-p3-4-1"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:getnexx:nxg-200:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "E23E0481-74FD-4F0C-926C-D303DF9F9E68"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "ics-cert@hq.dhs.gov"
}