CVE-2022-36228

Nokelock Smart padlock O1 Version 5.3.0 is vulnerable to Insecure Permissions. By sending a request, you can add any device and set the device password in the Nokelock app.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:janusintl:noke_standard_smart_padlock_firmware:5.3.0:*:*:*:*:*:*:*
cpe:2.3:h:janusintl:noke_standard_smart_padlock:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:janusintl:noke_hd_smart_padlock_firmware:5.3.0:*:*:*:*:*:*:*
cpe:2.3:h:janusintl:noke_hd_smart_padlock:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:janusintl:noke_hd\+_smart_padlock_firmware:5.3.0:*:*:*:*:*:*:*
cpe:2.3:h:janusintl:noke_hd\+_smart_padlock:-:*:*:*:*:*:*:*

History

12 Oct 2023, 18:37

Type Values Removed Values Added
New CVE

Information

Published : 2023-10-09 21:15

Updated : 2024-10-30 15:35


NVD link : CVE-2022-36228

Mitre link : CVE-2022-36228


JSON object : View

Products Affected

janusintl

  • noke_hd_smart_padlock_firmware
  • noke_standard_smart_padlock
  • noke_hd\+_smart_padlock_firmware
  • noke_hd\+_smart_padlock
  • noke_standard_smart_padlock_firmware
  • noke_hd_smart_padlock
CWE
CWE-862

Missing Authorization