CVE-2023-46892
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
23/01/2024
Last modified:
17/06/2025
Description
The radio frequency communication protocol being used by Meross MSH30Q 4.5.23 is vulnerable to replay attacks, allowing attackers to record and replay previously captured communication to execute unauthorized commands or actions (e.g., thermostat's temperature).
Impact
Base Score 3.x
8.80
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:meross:msh30q_firmware:4.5.23:*:*:*:*:*:*:* | ||
| cpe:2.3:h:meross:msh30q:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



