An issue was discovered in myStrom WiFi Switch V1 before 2.66, WiFi Switch V2 before 3.80, WiFi Switch EU before 3.80, WiFi Bulb before 2.58, WiFi LED Strip before 3.80, WiFi Button before 2.73, and WiFi Button Plus before 2.73. The cloud API had a hidden parameter, which allowed an authenticated user to reconfigure the server URL for a device registered to their account. In combination with an insecure device registration vulnerability, this allowed an attacker to reconfigure a maliciously registered device to their own rogue replica of the myStrom API and issue commands to the device, including firmware update commands.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Mystrom
Subscribe
|
Wifi Bulb
Subscribe
Wifi Bulb Firmware
Subscribe
Wifi Button
Subscribe
Wifi Button Firmware
Subscribe
Wifi Button Plus
Subscribe
Wifi Button Plus Firmware
Subscribe
Wifi Led Strip
Subscribe
Wifi Led Strip Firmware
Subscribe
Wifi Switch
Subscribe
Wifi Switch Eu
Subscribe
Wifi Switch Eu Firmware
Subscribe
Wifi Switch Firmware
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-7358 | An issue was discovered in myStrom WiFi Switch V1 before 2.66, WiFi Switch V2 before 3.80, WiFi Switch EU before 3.80, WiFi Bulb before 2.58, WiFi LED Strip before 3.80, WiFi Button before 2.73, and WiFi Button Plus before 2.73. The cloud API had a hidden parameter, which allowed an authenticated user to reconfigure the server URL for a device registered to their account. In combination with an insecure device registration vulnerability, this allowed an attacker to reconfigure a maliciously registered device to their own rogue replica of the myStrom API and issue commands to the device, including firmware update commands. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T09:54:03.476Z
Reserved: 2018-08-17T00:00:00.000Z
Link: CVE-2018-15480
No data.
Status : Modified
Published: 2018-08-30T17:29:01.613
Modified: 2024-11-21T03:50:54.217
Link: CVE-2018-15480
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD