CVE-2023-1748
Summary
| CVE | CVE-2023-1748 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-04-04 17:15:00 UTC |
| Updated | 2023-11-07 04:04:00 UTC |
| Description | The listed versions of Nexx Smart Home devices use hard-coded credentials. An attacker with unauthenticated access to the Nexx Home mobile application or the affected firmware could view the credentials and access the MQ Telemetry Server (MQTT) server and the ability to remotely control garage doors or smart plugs for any customer. |
Risk And Classification
Problem Types: CWE-798
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Getnexx | Nxal-100 | - | All | All | All |
| Operating System | Getnexx | Nxal-100 Firmware | All | All | All | All |
| Hardware | Getnexx | Nxg-100b | - | All | All | All |
| Operating System | Getnexx | Nxg-100b Firmware | All | All | All | All |
| Hardware | Getnexx | Nxg-200 | - | All | All | All |
| Operating System | Getnexx | Nxg-200 Firmware | All | All | All | All |
| Hardware | Getnexx | Nxpg-100w | - | All | All | All |
| Operating System | Getnexx | Nxpg-100w Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Nexx Smart Home Device | CISA | MISC | www.cisa.gov | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.