NA

CVE-2023-42143

Published: 23/01/2024 Updated: 31/01/2024
CVSS v3 Base Score: 5.4 | Impact Score: 2.7 | Exploitability Score: 2.3

Vulnerability Summary

Missing Integrity Check in Shelly TRV 20220811-152343/v2.1.8@5afc928c allows malicious users to create a backdoor by redirecting the device to an attacker-controlled machine which serves the manipulated firmware file. The device is updated with the manipulated firmware.

Vulnerable Product Search on Vulmon Subscribe to Product

shelly trv_firmware 2.1.8