The listed versions of Nexx Smart Home devices use hard-coded credentials. An attacker with unauthenticated access to the Nexx Home mobile application or the affected firmware could view the credentials and access the MQ Telemetry Server (MQTT) server and the ability to remotely control garage doors or smart plugs for any customer.
Metrics
Affected Vendors & Products
References
History
Thu, 16 Jan 2025 22:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|

Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2025-01-16T21:36:21.307Z
Reserved: 2023-03-30T20:01:18.851Z
Link: CVE-2023-1748

Updated: 2024-08-02T05:57:25.127Z

Status : Modified
Published: 2023-04-04T17:15:07.060
Modified: 2024-11-21T07:39:49.367
Link: CVE-2023-1748

No data.