Authentication Bypass by Capture-replay in Sinilink Wifi Remote Thermostat



Published: 2023-01-23
Risk Medium
Patch available NO
Number of vulnerabilities 1
CVE-ID CVE-2022-43704
CWE-ID CWE-294
Exploitation vector Network
Public exploit N/A
Vulnerable software
Subscribe
XY-WFTX Wifi Remote Thermostat Module Temperature Controller
Hardware solutions / Other hardware appliances

Vendor Sinilink

Security Bulletin

This security bulletin contains one medium risk vulnerability.

1) Authentication Bypass by Capture-replay

EUVDB-ID: #VU71416

Risk: Medium

CVSSv3.1: 6.9 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:U/RL:U/RC:C]

CVE-ID: CVE-2022-43704

CWE-ID: CWE-294 - Authentication Bypass by Capture-replay

Exploit availability: No

Description

The vulnerability allows a remote attacker to bypass authentication process.

The vulnerability exists due to authentication bypass by capture-replay. A remote attacker can control the onboard relay without requiring authentication via the mobile application.

Mitigation

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

Vulnerable software versions

XY-WFTX Wifi Remote Thermostat Module Temperature Controller: 1.3.6

External links

http://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/cve-2022-43704-capture-replay-vulnerability-in-sinilink-xy-wft1-thermostat/


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.



###SIDEBAR###