Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
VOBOT CLOCK before 0.99.30 devices do not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information, and consequently execute arbitrary code, via a crafted certificate, as demonstrated by leveraging a hardcoded --no-check-certificate Wget option.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
VOBOT CLOCK 安全漏洞
Vulnerability Description
VOBOT CLOCK是一款智能时钟产品。该产品具有音乐播放、语音交互和天气预报等功能。 VOBOT CLOCK 0.99.30之前版本中存在安全漏洞,该漏洞源于程序没有验证SSL服务器中的证书。攻击者可借助特制的证书利用该漏洞伪造服务器并获取敏感信息,从而执行任意代码。
CVSS Information
N/A
Vulnerability Type
N/A