CVE-2023-1083
Severity CVSS v4.0:
Pending analysis
Type:
CWE-306
Missing Authentication for Critical Function
Publication date:
09/04/2024
Last modified:
21/11/2024
Description
An unauthenticated remote attacker who is aware of a MQTT topic name can send and receive messages, including GET/SET configuration commands, reboot commands and firmware updates.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL