CVE-2023-46723 Information

Description

lte-pic32-writer is a writer for PIC32 devices. In versions 0.0.1 and prior those who use sendto.txt are vulnerable to attackers who known the IMEI reading the sendto.txt. The sendto.txt file can contain the SNS(such as slack and zulip) URL and API key. As of time of publication a patch is not yet available. As workarounds avoid using sendto.txt or use .htaccess to block access to sendto.txt.

Reference

https://github.com/paijp/lte-pic32-writer/security/advisories/GHSA-9qgg-ph2v-v4mh

Share on: