CVE-2022-31277
Description
Xiaomi Lamp 1 v2.0.4_0066 was discovered to be vulnerable to replay attacks. This allows attackers to to bypass the expected access restrictions and gain control of the switch and other functions via a crafted POST request.
References
ExploitThird Party Advisory
CvssV3 impact
Could not find any metrics
CvssV2 impact
AccessComplexity | LOW |
ConfidentialityImpact | PARTIAL |
AvailabilityImpact | PARTIAL |
IntegrityImpact | PARTIAL |
BaseScore | 5.800000190734863 |
VectorString | AV:A/AC:L/Au:N/C:P/I:P/A:P |
Version | 2.0 |
AccessVector | ADJACENT_NETWORK |
Authentication | NONE |