CVE-2018-15476
Last modified
CVE-2018-15476 is a vulnerability of currently unknown severity. An issue was discovered in myStrom WiFi Switch V1 before 2.66, WiFi Switch V2 before 3.80, WiFi Switch EU before 3.80, WiFi Bulb before 2.58, WiFi LED Strip before 3.80, WiFi Button before 2.73, and WiFi Button Plus before 2.73. The SSL/TLS server certificate in the device to cloud communication was not verified by the device. EPSS estimates a 0.76% chance of exploitation in the next 30 days.
Description
An issue was discovered in myStrom WiFi Switch V1 before 2.66, WiFi Switch V2 before 3.80, WiFi Switch EU before 3.80, WiFi Bulb before 2.58, WiFi LED Strip before 3.80, WiFi Button before 2.73, and WiFi Button Plus before 2.73. The SSL/TLS server certificate in the device to cloud communication was not verified by the device. As a result, an attacker in control of the network traffic of a device could have taken control of a device by intercepting and modifying commands issued from the server to the device in a Man-in-the-Middle attack. This included the ability to inject firmware update commands into the communication and cause the device to install maliciously modified firmware.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mystrom | Wifi Switch Firmware | < 2.66 |
| Mystrom | Wifi Switch Firmware | < 3.80 |
| Mystrom | Wifi Button Plus Firmware | < 2.73 |
| Mystrom | Wifi Button Firmware | < 2.73 |
| Mystrom | Wifi Switch Eu Firmware | < 3.80 |
| Mystrom | Wifi Bulb Firmware | < 2.58 |
| Mystrom | Wifi Led Strip Firmware | < 3.80 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-15476?
How severe is CVE-2018-15476?
How do I fix CVE-2018-15476?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-1547IBM Robotic Process Automation with Automation Anywhere 10.0…8
- CVE-2018-15470An issue was discovered in Xen through 4.11.x. The logic in …
- CVE-2018-15471An issue was discovered in xenvif_set_hash_mapping in driver…7.8
- CVE-2018-15472An issue was discovered in GitLab Community and Enterprise E…7.5
- CVE-2018-15473OpenSSH through 7.7 is prone to a user enumeration vulnerabi…5.3
- CVE-2018-15474CSV Injection (aka Excel Macro Injection or Formula Injectio…
- CVE-2018-15477myStrom WiFi Switch V1 devices before 2.66 did not sanitize …
- CVE-2018-15478An issue was discovered in myStrom WiFi Switch V1 before 2.6…
- CVE-2018-15479An issue was discovered in myStrom WiFi Switch V1 before 2.6…
- CVE-2018-1548IBM API Connect 2018.1.0.0, 2018.2.1, 2018.2.2, 2018.2.3, an…4.3
- CVE-2018-15480An issue was discovered in myStrom WiFi Switch V1 before 2.6…
- CVE-2018-15481Improper input sanitization within the restricted administra…
Are you affected by CVE-2018-15476?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
