Missing authorization in Bosh products - CVE-2023-49722
Published: January 16, 2024
BCC101
BCC102
BCC50
Bosh
Description
The vulnerability allows a remote attacker to compromise the affected device.
The vulnerability exists due to missing authorization when accessing the BCC101/BCC102/BCC50 thermostat products by directly connecting to port 8899/TCP. A remote attacker on the local network can connect to the device and gain full control over the thermostat.