Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The Magic Home Pro application 1.5.1 for Android allows Authentication Bypass. The security control that the application currently has in place is a simple Username and Password authentication function. Using enumeration, an attacker is able to forge a User specific token without the need for correct password to gain access to the mobile application as that victim user.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Magic Pro Home 授权问题漏洞
Vulnerability Description
Magic Pro Home是中国Magic Pro公司的一款可以智能控制LED灯照明的移动端软件。 Magic Pro Home application 1.5.1 存在安全漏洞,该漏洞源于允许绕过身份验证。应用程序当前具有的安全控制是一个简单的用户名和密码身份验证功能。使用枚举,攻击者可利用该漏洞能够伪造用户特定的令牌,而不需要正确的密码来获得作为受害者的移动应用程序的访问权。
CVSS Information
N/A
Vulnerability Type
N/A