CVE-2023-1748 CRITICAL

CVE-2023-1748: CVE-2023-1748

Vendor Nexx
Product Smart Alarm NXAL-100
Published April 4, 2023
Last update January 16, 2025

CVSS base score

9.3/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality High
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L

What the vulnerability does

01Description

The listed versions of Nexx Smart Home devices use hard-coded credentials. An attacker with unauthenticated access to the Nexx Home mobile application or the affected firmware could view the credentials and access the MQ Telemetry Server (MQTT) server and the ability to remotely control garage doors or smart plugs for any customer.

Key dates

02Disclosure timeline

April 4, 2023 CVE published
January 16, 2025 Record updated