SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2018-15480

The cloud API had a hidden parameter, which allowed an authenticated user to reconfigure the server URL for a device registered to their account.

HIGH 8.8EPSS 1.02%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (1.02%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

An issue was discovered in myStrom WiFi Switch V1 before 2.66, WiFi Switch V2 before 3.80, WiFi Switch EU before 3.80, WiFi Bulb before 2.58, WiFi LED Strip before 3.80, WiFi Button before 2.73, and WiFi Button Plus before 2.73. The cloud API had a hidden parameter, which allowed an authenticated user to reconfigure the server URL for a device registered to their account. In combination with an insecure device registration vulnerability, this allowed an attacker to reconfigure a maliciously registered device to their own rogue replica of the myStrom API and issue commands to the device, including firmware update commands.

CVSS 3.0
8.8 HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS
1.02% probability · 62th percentile
CISA KEV
Not listed
Affected
mystrom/wifi switch firmware · mystrom/wifi button plus firmware · mystrom/wifi button firmware · mystrom/wifi switch eu firmware · mystrom/wifi bulb firmware · mystrom/wifi led strip firmware
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.