Aller au contenu

Fiche vulnérabilité

CVE-2022-2107 : faille critique micodus mv720 firmware (CVSS 9.8)

Description

The MiCODUS MV720 GPS tracker API server has an authentication mechanism that allows devices to use a hard-coded master password. This may allow an attacker to send SMS commands directly to the GPS tracker as if they were coming from the GPS owner’s mobile number.

En bref

Sévérité
Critique (CVSS 9.8)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
20 juil. 2022
Dernière mise à jour
17 juin 2026

Produits concernés

  • micodus mv720 firmware

Références

Rechercher une autre vulnérabilité dans la base CVE