CVE Database
/

CVE-2023-1083

Back to search

CVE-2023-1083

Published: Apr 9, 2024

Modified: Oct 2, 2024

PUBLISHED

CVSS v3.1

9.8

CRITICAL

Description

An unauthenticated remote attacker who is aware of a MQTT topic name can send and receive messages, including GET/SET configuration commands, reboot commands and firmware updates.

VendorProductVersions

Welotec

TK515L

affected
0 - < v2.3.0.r5542

Welotec

TK515L Set

affected
0 - < v2.3.0.r5542

Welotec

TK515L-W

affected
0 - < v2.3.0.r5542

Welotec

TK515L-W Set

affected
0 - < v2.3.0.r5542

Welotec

TK525L

affected
0 - < v2.3.0.r5542

Welotec

TK525L Set

affected
0 - < v2.3.0.r5542

Welotec

TK525L-W

affected
0 - < v2.3.0.r5542

Welotec

TK525L-W Set

affected
0 - < v2.3.0.r5542

Welotec

TK525U

affected
0 - < v2.3.0.r5542

Welotec

TK525U Set

affected
0 - < v2.3.0.r5542

Welotec

TK525W

affected
0 - < v2.3.0.r5542

Welotec

TK525W Set

affected
0 - < v2.3.0.r5542

Welotec

TK535L1

affected
0 - < v2.3.0.r5542

Welotec

TK535L1 Set

affected
0 - < v2.3.0.r5542

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector

Network

Attack Complexity

Low

Privileges Required

None

User Interaction

None

Scope

Unchanged

Confidentiality

High

Integrity

High

Availability

High

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now