CVE-2019-11063 Information
Feb 14, 2021
cve
Description
A broken access control vulnerability in SmartHome app (Android versions up to 3.0.42_190515 ios versions up to 2.0.22) allows an attacker in the same local area network to list user accounts and control IoT devices that connect with its gateway (HG100) via http://[target]/smarthome/devicecontrol without any authentication. CVSS 3.0 base score 10 (Confidentiality Integrity and Availability impacts). CVSS vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).
CVSS Vector
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Reference
http://surl.twcert.org.tw/5LWQJ http://surl.twcert.org.tw/5LWQJ https://github.com/tim124058/ASUS-SmartHome-Exploit/ https://tvn.twcert.org.tw/taiwanvn/TVN-201908014
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
8.8
Share on: