CVE-2023-1749

Publication date

2023-04-04 16:54:46

Family

icscert

State

PUBLISHED

Description

The listed versions of Nexx Smart Home devices lack proper access control when executing actions. An attacker with a valid NexxHome deviceId could send API requests that the affected devices would execute.