SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-9659

The Chuango 433 MHz burglar-alarm product line uses static codes in the RF remote control, allowing an attacker to arm, disarm, or trigger the alarm remotely via replay attacks, as demonstrated by Chuango branded products, and non-Chuango branded…

CRITICAL 9.1EPSS 1.33%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (1.33%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

The Chuango 433 MHz burglar-alarm product line uses static codes in the RF remote control, allowing an attacker to arm, disarm, or trigger the alarm remotely via replay attacks, as demonstrated by Chuango branded products, and non-Chuango branded products such as the Eminent EM8617 OV2 Wifi Alarm System.

CVSS 3.0
9.1 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
EPSS
1.33% probability · 69th percentile
CISA KEV
Not listed
Weakness
CWE-294
Affected
chuango/wifi alarm system firmware · chuango/wifi\/cellular smart home system h4 plus firmware · chuango/awv plus wifi alarm system firmware · chuango/g5w 3g firmware · chuango/g5 plus gsm\/sms\/rfid touch alarm system firmware · chuango/g3 gsm\/sms alarm system firmware · chuango/b11 dual-network alarm system firmware · chuango/a8 pstn alarm system firmware · chuango/a11 pstn\/lcd\/rfid touch alarm system firmware · chuango/cg-105s on-site alarm system firmware · eminent/em8617 ov2 wifi alarm system firmware
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.