CVE-2023-1749 Information

Description

The listed versions of Nexx Smart Home devices lack proper access control when executing actions. An attacker with a valid NexxHome deviceId could send API requests that the affected devices would execute.

Reference

https://www.cisa.gov/news-events/ics-advisories/icsa-23-094-01

Share on: