Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%
Get alerts for future matching vulnerabilitiesLog in to subscribe
I. Basic Information for CVE-2023-2626
Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Authentication Bypass in OpenThread Boarder Router devices
Source: NVD (National Vulnerability Database)
Vulnerability Description
There exists an authentication bypass vulnerability in OpenThread border router devices and implementations. This issue allows unauthenticated nodes to craft radio frames using “Key ID Mode 2”: a special mode using a static encryption key to bypass security checks, resulting in arbitrary IP packets being allowed on the Thread network. This provides a pathway for an attacker to send/receive arbitrary IPv6 packets to devices on the LAN, potentially exploiting them if they lack additional authentication or contain any network vulnerabilities that would normally be mitigated by the home router’s NAT firewall. Effected devices have been mitigated through an automatic update beyond the affected range.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Source: NVD (National Vulnerability Database)
Vulnerability Type
认证机制不恰当
Source: NVD (National Vulnerability Database)
Vulnerability Title
Google Nest 授权问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Google Nest是美国谷歌(Google)公司的一款智能家居产品。 Google Nest存在安全漏洞。该漏洞允许未经身份验证的节点使用“Key ID Mode 2”来伪造无线电帧,这是一种使用静态加密密钥绕过安全检查的特殊模式,从而允许任意 IP 数据包传输到 Thread 网络中。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)
Affected Products
VendorProductAffected VersionsCPESubscribe
GoogleNest Hub Max 10.20221207.2.109 ~ 10.20221207.2.120 -
GoogleNest Hub (2nd. gen) w/ Sleep Tracking 10.20221207.2.100038 ~ 10.20221207.2.100042 -
GoogleNest Wifi 6E 1.59 ~ 1.63.355999 -
GoogleGoogle Wifi (next gen) 14150.881.7 ~ 14150.882.9 -
GoogleNest Wifi Point 1.56.1 ~ 1.56.368671 -
GoogleNest Hub Max 10.20221207.2.109 ~ 10.20221207.2.120 -
GoogleNest Hub (2nd. gen) w/ Sleep Tracking 10.20221207.2.100038 ~ 10.20221207.2.100042 -
II. Public POCs for CVE-2023-2626
#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC
III. Intelligence Information for CVE-2023-2626
Please Login to view more intelligence information
IV. Related Vulnerabilities
V. Comments for CVE-2023-2626

No comments yet


Leave a comment