CVE-2023-22601 CRITICAL

CVE-2023-22601

Vendor Inhand Networks
Product InRouter 302
Weakness CWE-330 · Insufficient randomness
Published January 12, 2023
Last update January 16, 2025

CVSS base score

10.0/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality Low
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:H

What the vulnerability does

01Description

InHand Networks InRouter 302, prior to version IR302 V3.5.56, and InRouter 615, prior to version InRouter6XX-S-V2.3.0.r5542, contain vulnerability CWE-330: Use of Insufficiently Random Values. They do not properly randomize MQTT ClientID parameters. An unauthorized user could calculate this parameter and use it to gather additional information about other InHand devices managed on the same cloud platform.

Key dates

02Disclosure timeline

January 12, 2023 CVE published
January 16, 2025 Record updated