Meross Smart Wi-Fi 2 Way Wall Switch (MSS550X), on its 3.1.3 version and before, creates an open Wi-Fi Access Point without the required security measures in its initial setup. This could allow a remote attacker to obtain the Wi-Fi SSID as well as the password configured by the user from Meross app via Http/JSON plain request.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published: 2021-11-05T19:41:27

Updated: 2024-08-03T17:09:09.214Z

Reserved: 2021-09-06T00:00:00

Link: CVE-2021-3774

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-11-05T21:15:08.480

Modified: 2023-11-20T14:15:07.210

Link: CVE-2021-3774

cve-icon Redhat

No data.