CVE-2023-5499

Published Oct 10, 2023

Last updated a year ago

Overview

Description
Information exposure vulnerability in Shenzhen Reachfar v28, the exploitation of which could allow a remote attacker to retrieve all the week's logs stored in the 'log2' directory. An attacker could retrieve sensitive information such as remembered wifi networks, sent messages, SOS device locations and device configurations.
Source
cve-coordination@incibe.es
NVD status
Modified

Risk scores

CVSS 3.1

Type
Primary
Base score
7.5
Impact score
3.6
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Severity
HIGH

Weaknesses

cve-coordination@incibe.es
CWE-532
nvd@nist.gov
CWE-532

Social media

Hype score
Not currently trending

Configurations