CVE-2019-11063
A broken access control vulnerability in SmartHome app (Android versions up to 3.0.42_190515, ios versions up to 2.0.22) allows an attacker in the same local area network to list user accounts and control IoT devices that connect with its gateway…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (4.45%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A broken access control vulnerability in SmartHome app (Android versions up to 3.0.42_190515, ios versions up to 2.0.22) allows an attacker in the same local area network to list user accounts and control IoT devices that connect with its gateway (HG100) via http://[target]/smarthome/devicecontrol without any authentication. CVSS 3.0 base score 10 (Confidentiality, Integrity and Availability impacts). CVSS vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).
- CVSS 3.0
- 8.8 HIGHCVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 4.45% probability · 91th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-306
- Affected
- asus/smarthome
- Source
- twcert@cert.org.tw
References
- http://surl.twcert.org.tw/5LWQJThird Party Advisory
- https://github.com/tim124058/ASUS-SmartHome-Exploit/Exploit, Third Party Advisory
- https://tvn.twcert.org.tw/taiwanvn/TVN-201908014Third Party Advisory
- http://surl.twcert.org.tw/5LWQJThird Party Advisory
- https://github.com/tim124058/ASUS-SmartHome-Exploit/Exploit, Third Party Advisory
- https://tvn.twcert.org.tw/taiwanvn/TVN-201908014Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.