NA

CVE-2022-45636

Published: 21/03/2023 Updated: 08/08/2023
CVSS v3 Base Score: 8.1 | Impact Score: 5.2 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

An issue discovered in MEGAFEIS, BOFEI DBD+ Application for IOS & Android v1.4.4 allows malicious user to unlock model(s) without authorization via arbitrary API requests.

Vulnerable Product Search on Vulmon Subscribe to Product

megafeis bofei dbd\\+ 1.4.4

megafeis bofei dbd\\+ 1.4.3

Github Repositories

PoC Code for Vulnerabilities Found in MEGAFEIS-branded Smart Locks & their Mobile Companion App: DBD+

megafeis-palm The contents of this repository were produced by Abdullah Ansari during his time at WithSecure All contents are licensed to WithSecure as described in the attached license file within this repository Welcome to the 🤦‍♂️ megafeis-palm 🤦‍♂️ repository This repo contains proof-of-concept (PoC) code for vulnerabilities I discovered in the DB