Security Advisory

CVE-2022-2107

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2022-07-20 15:24:35
Last updated 2025-04-16 16:14:52
Assigner icscert
State PUBLISHED

Description

The MiCODUS MV720 GPS tracker API server has an authentication mechanism that allows devices to use a hard-coded master password. This may allow an attacker to send SMS commands directly to the GPS tracker as if they were coming from the GPS owner’s mobile number.