CVE-2023-42470
The Imou Life com.mm.android.smartlifeiot application through 6.8.0 for Android allows Remote Code Execution via a crafted intent to an exported component.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.49%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The Imou Life com.mm.android.smartlifeiot application through 6.8.0 for Android allows Remote Code Execution via a crafted intent to an exported component. This relates to the com.mm.android.easy4ip.MainActivity activity. JavaScript execution is enabled in the WebView, and direct web content loading occurs.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 2.49% probability · 84th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-94
- Affected
- imoulife/life
- Source
- cve@mitre.org
References
- https://github.com/actuator/cve/blob/main/CVE-2023-42470Third Party Advisory
- https://github.com/actuator/imou/blob/main/imou-life-6.8.0.mdExploit
- https://github.com/actuator/imou/blob/main/poc.apkExploit
- https://github.com/actuator/cve/blob/main/CVE-2023-42470Third Party Advisory
- https://github.com/actuator/imou/blob/main/imou-life-6.8.0.mdExploit
- https://github.com/actuator/imou/blob/main/poc.apkExploit
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.