Impact
A flaw in the provisioning process of the Prolink 13A Smart Plug allows an attacker to feed a specially crafted packet that can halt the device’s operation or cause it to establish a connection with an adversary‐controlled endpoint. The resulting denial of service disrupts the plug’s normal functionality, while the unexpected outbound link can enable the attacker to exploit the device as a pivot for further network activities. The weakness is an input validation error, categorized as CWE‑20.
Affected Systems
The affected device is the Prolink 13A Smart Plug model DS‑3202M‑UKv3 Wi‑Fi, running the mEzee application version 2.6.7. No other vendor or product variants are listed as impacted in the current data.
Risk and Exploitability
The CVSS base score of 7.5 indicates a high‑severity vulnerability; however, the EPSS score is not available and the flaw is not yet listed in CISA’s KEV catalog, suggesting that mass exploitation has not yet been observed. An attacker would normally need to transmit the forged packet during the device’s provisioning phase, which typically occurs on the local network or device‑to‑controller channel, implying that physical proximity or local‑network access is required. The description does not detail a public exploit, so the risk is primarily theoretical until an exploit or additional user‑reports emerge.
OpenCVE Enrichment