CRITICAL🇵🇱 Wersja polska

CVE-2023-22600

CVSS 10.0v3.1pub. 2023-01-12upd. 2024-11-21

InHand Networks InRouter 302, prior to version IR302 V3.5.56, and InRouter 615, prior to version InRouter6XX-S-V2.3.0.r5542, contain vulnerability CWE-284: Improper Access Control. They allow unauthenticated devices to subscribe to MQTT topics on the same network as the device manager. An unauthorized user who knows of an existing topic name could send and receive messages to and from that topic. This includes the ability to send GET/SET configuration commands, reboot commands, and push firmware updates.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:H
  • Inhandnetworks Inrouter302

    HW
    Inhandnetworks
    all versions
  • Inhandnetworks Inrouter302 Firmware

    OS
    Inhandnetworks
    < 3.5.56
  • Inhandnetworks Inrouter615 S

    HW
    Inhandnetworks
    all versions
  • Inhandnetworks Inrouter615 S Firmware

    OS
    Inhandnetworks
    < 2.3.0.r5542
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2023-22601CRITICAL10.0PL ✓same product

InHand Networks InRouter 302/615 — słaba losowość MQTT ClientID

CVE-2022-25932CRITICAL9.8PL ✓same product

Niekompletne poprawki privilege escalation w InHand Networks InRouter302

CVE-2023-22599HIGH7.0same product

InHand Networks InRouter 302, prior to version IR302 V3.5.56, and InRouter 615, prior to version InRouter6XX-...

CVE-2023-22598HIGH7.2same product

InHand Networks InRouter 302, prior to version IR302 V3.5.56, and InRouter 615, prior to version InRouter6XX-...

CVE-2022-21182HIGH8.8same product

A privilege escalation vulnerability exists in the router configuration import functionality of InHand Network...