CVE-2023-37822
Last modified
CVE-2023-37822 is a high-severity vulnerability rated 8.2/10 on the CVSS scale. The Eufy Homebase 2 before firmware version 3.3.4.1h creates a dedicated wireless network for its ecosystem, which serves as a proxy to the end user's primary network. The WPA2-PSK generation of this dedicated network is flawed and solely based on the serial number. EPSS estimates a 0.26% chance of exploitation in the next 30 days.
Description
The Eufy Homebase 2 before firmware version 3.3.4.1h creates a dedicated wireless network for its ecosystem, which serves as a proxy to the end user's primary network. The WPA2-PSK generation of this dedicated network is flawed and solely based on the serial number. Due to the flawed generation process, the WPA2-PSK can be brute forced offline within seconds. This vulnerability allows an attacker in proximity to the dedicated wireless network to gain unauthorized access to the end user's primary network. The only requirement of the attack is proximity to the dedicated wireless network.
Metrics
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Eufy | Homebase 2 Firmware | < 3.3.4.1h |
References
- https://www.usenix.org/conference/woot24/presentation/goemanTechnical Description
- https://www.usenix.org/system/files/woot24-goeman.pdfTechnical Description
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-37822?
How severe is CVE-2023-37822?
How do I fix CVE-2023-37822?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-37808Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2023-37809Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2023-3781there is a possible use-after-free write due to improper loc…7.8
- CVE-2023-37810Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2023-37811Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2023-3782DoS of the OkHttp client when using a BrotliInterceptor and …5.9
- CVE-2023-37824Sitolog sitologapplicationconnect v7.8.a and before was disc…9.8
- CVE-2023-37826A cross-site scripting (XSS) vulnerability in General Soluti…6.1
- CVE-2023-37827A cross-site scripting (XSS) vulnerability in General Soluti…6.1
- CVE-2023-37828A cross-site scripting (XSS) vulnerability in General Soluti…6.1
- CVE-2023-37829A cross-site scripting (XSS) vulnerability in General Soluti…6.1
- CVE-2023-3783A vulnerability was found in Webile 1.0.1. It has been class…5.4
Are you affected by CVE-2023-37822?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
