The main MiCODUS MV720 GPS tracker web server has an authenticated insecure direct object references vulnerability on endpoint and POST parameter “Device ID,” which accepts arbitrary device IDs.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published: 2022-07-20T15:24:26.564063Z

Updated: 2024-09-17T02:42:35.600Z

Reserved: 2022-06-24T00:00:00

Link: CVE-2022-33944

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2022-07-20T16:15:09.160

Modified: 2022-07-27T21:42:16.190

Link: CVE-2022-33944

cve-icon Redhat

No data.