All CVEs — page 131 of 242
The complete archive, 25 per page, newest first. 6034 records. Search instead.
The lwIP TCP/IP Stack MQTT implementation is vulnerable to an out-of-bounds write, enabling full code execution on the device. This flaw is critical as it allows attackers to gain control over the device.
The vulnerability allows unauthenticated remote attackers to gain unauthorized write access to the file system with elevated privileges, potentially leading to a full system compromise.
The flaw involves default, hard-coded credentials in the Analytics and Location Engine (ALE), allowing unauthenticated attackers to gain unauthorized access to the application and underlying system.