CVE-2023-35835
Last modified
CVE-2023-35835 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. An issue was discovered in SolaX Pocket WiFi 3 through 3.001.02. The device provides a WiFi access point for initial configuration. EPSS estimates a 0.51% chance of exploitation in the next 30 days.
Description
An issue was discovered in SolaX Pocket WiFi 3 through 3.001.02. The device provides a WiFi access point for initial configuration. The WiFi network provided has no network authentication (such as an encryption key) and persists permanently, including after enrollment and setup is complete. The WiFi network serves a web-based configuration utility, as well as an unauthenticated ModBus protocol interface.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Solax | Pocket Wifi 3 Firmware | >= 3.0.0, <= 3.009.03_20230504 |
References
- https://www.solaxpower.com/downloads/Not Applicable
- https://yougottahackthat.com/blog/Third Party Advisory
- https://www.solaxpower.com/downloads/Not Applicable
- https://yougottahackthat.com/blog/Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-35835?
How severe is CVE-2023-35835?
How do I fix CVE-2023-35835?
Are you affected by CVE-2023-35835?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
