The Eques elf smart plug and the mobile app use a hardcoded AES 256 bit key to encrypt the commands and responses between the device and the app. The communication happens over UDP port 27431. An attacker on the local network can use the same key to encrypt and send commands to discover all smart plugs in a network, take over control of a device, and perform actions such as turning it on and off.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2019-08-29T12:40:53
Updated: 2024-08-05T00:56:22.397Z
Reserved: 2019-08-28T00:00:00
Link: CVE-2019-15745
Vulnrichment
No data.
NVD
Status : Modified
Published: 2019-08-29T13:15:11.227
Modified: 2024-11-21T04:29:23.397
Link: CVE-2019-15745
Redhat
No data.