CVE-2018-15480
Summary
| CVE | CVE-2018-15480 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-08-30 17:29:00 UTC |
| Updated | 2019-10-03 00:03:00 UTC |
| Description | An issue was discovered in myStrom WiFi Switch V1 before 2.66, WiFi Switch V2 before 3.80, WiFi Switch EU before 3.80, WiFi Bulb before 2.58, WiFi LED Strip before 3.80, WiFi Button before 2.73, and WiFi Button Plus before 2.73. The cloud API had a hidden parameter, which allowed an authenticated user to reconfigure the server URL for a device registered to their account. In combination with an insecure device registration vulnerability, this allowed an attacker to reconfigure a maliciously registered device to their own rogue replica of the myStrom API and issue commands to the device, including firmware update commands. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Mystrom | Wifi Bulb | - | All | All | All |
| Hardware | Mystrom | Wifi Bulb | - | All | All | All |
| Operating System | Mystrom | Wifi Bulb Firmware | All | All | All | All |
| Operating System | Mystrom | Wifi Bulb Firmware | All | All | All | All |
| Hardware | Mystrom | Wifi Button | - | All | All | All |
| Hardware | Mystrom | Wifi Button | - | All | All | All |
| Operating System | Mystrom | Wifi Button Firmware | All | All | All | All |
| Operating System | Mystrom | Wifi Button Firmware | All | All | All | All |
| Hardware | Mystrom | Wifi Button Plus | - | All | All | All |
| Hardware | Mystrom | Wifi Button Plus | - | All | All | All |
| Operating System | Mystrom | Wifi Button Plus Firmware | All | All | All | All |
| Operating System | Mystrom | Wifi Button Plus Firmware | All | All | All | All |
| Hardware | Mystrom | Wifi Led Strip | - | All | All | All |
| Hardware | Mystrom | Wifi Led Strip | - | All | All | All |
| Operating System | Mystrom | Wifi Led Strip Firmware | All | All | All | All |
| Operating System | Mystrom | Wifi Led Strip Firmware | All | All | All | All |
| Hardware | Mystrom | Wifi Switch | v1 | All | All | All |
| Hardware | Mystrom | Wifi Switch | v2 | All | All | All |
| Hardware | Mystrom | Wifi Switch | v1 | All | All | All |
| Hardware | Mystrom | Wifi Switch | v2 | All | All | All |
| Hardware | Mystrom | Wifi Switch Eu | - | All | All | All |
| Hardware | Mystrom | Wifi Switch Eu | - | All | All | All |
| Operating System | Mystrom | Wifi Switch Eu Firmware | All | All | All | All |
| Operating System | Mystrom | Wifi Switch Eu Firmware | All | All | All | All |
| Operating System | Mystrom | Wifi Switch Firmware | All | All | All | All |
| Operating System | Mystrom | Wifi Switch Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.swisscom.ch/content/dam/swisscom/de/about/nachhaltigkeit/digitale-schweiz... | MISC | www.swisscom.ch | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.