Impact
A flaw in Insta's InstaKNXServiceApp firmware update handler allows an attacker to bypass data authenticity checks when the CreateWebClientAndDownloadFileList function is invoked. Based on the description, it is inferred that the attacker may be able to tamper with the firmware update payload, potentially leading to compromised device integrity or availability. The weakness is identified as CWE‑345, indicating insufficient verification of data authenticity.
Affected Systems
Insta's InstaKNXServiceApp, specifically version 1.2.3.1469, is impacted. No other versions or products are listed.
Risk and Exploitability
The CVSS score of 6.3 indicates a moderate severity assessment. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting no widely documented exploitation yet. The attack vector is remote, but the description notes that exploitation is highly complex and difficult, which may reduce the likelihood of an immediate real‑world attack.
OpenCVE Enrichment