CVE-2022-31462

Severity CVSS v4.0:
Pending analysis
Type:
CWE-798 Use of Hard-coded Credentials
Publication date:
02/06/2022
Last modified:
08/07/2022

Description

Owl Labs Meeting Owl 5.2.0.15 allows attackers to control the device via a backdoor password (derived from the serial number) that can be found in Bluetooth broadcast data.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:owllabs:meeting_owl_pro_firmware:*:*:*:*:*:*:*:* 5.4.2.3 (excluding)
cpe:2.3:h:owllabs:meeting_owl_pro:-:*:*:*:*:*:*:*