Missing Integrity Check in Shelly TRV 20220811-152343/v2.1.8@5afc928c allows malicious users to create a backdoor by redirecting the device to an attacker-controlled machine which serves the manipulated firmware file. The device is updated with the manipulated firmware.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 30 May 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-05-30T14:20:57.766Z
Reserved: 2023-09-08T00:00:00.000Z
Link: CVE-2023-42143
Updated: 2024-08-02T19:16:50.595Z
Status : Modified
Published: 2024-01-23T20:15:45.097
Modified: 2025-05-30T15:15:22.783
Link: CVE-2023-42143
No data.
OpenCVE Enrichment
No data.
Weaknesses