漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Aqara hardcoded OAuth client credentials
Vulnerability Description
The Aqara IAM/SSO Gateway (gw-builder.aqara.com) used a hardcoded OAuth client credential, which is an instance of "CWE-798: Use of Hard-coded Credentials." This issue has an estimated CVSS of CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N (9.1 Critical). When combined with CVE-2026-50082, CVE-50084, and CVE-50085, this can lead to a fully unauthenticated, remote takeover of affected devices.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Vulnerability Type
使用硬编码的凭证
Vulnerability Title
Aqara IAM/SSO Gateway 信任管理问题漏洞
Vulnerability Description
Aqara IAM/SSO Gateway是美国Aqara公司的一个身份认证与访问管理网关。 Aqara IAM/SSO Gateway存在信任管理问题漏洞,该漏洞源于使用了硬编码的OAuth客户端凭据,可能导致未经身份验证的攻击者远程接管受影响的设备。
CVSS Information
N/A
Vulnerability Type
N/A