CVE-2023-30399

Insecure permissions in the settings page of GARO Wallbox GLB/GTB/GTC before v189 allows attackers to redirect users to a crafted update package link via a man-in-the-middle attack.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:garo:wallbox_glb_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:garo:wallbox_glb:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:garo:wallbox_gtb_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:garo:wallbox_gtb:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:garo:wallbox_gtc_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:garo:wallbox_gtc:-:*:*:*:*:*:*:*

History

29 Jan 2025, 20:15

Type Values Removed Values Added
References (MISC) https://github.com/Yof3ng/IoT/blob/master/Garo/CVE-2023-30399.md - Exploit, Third Party Advisory () https://github.com/Yof3ng/IoT/blob/master/Garo/CVE-2023-30399.md - Exploit, Third Party Advisory
References (MISC) https://www.garo.se/ - Product () https://www.garo.se/ - Product
References (MISC) http://garocharging.com/glb-wallbox/ - Product () http://garocharging.com/glb-wallbox/ - Product

12 May 2023, 17:38

Type Values Removed Values Added
First Time Garo wallbox Gtc
Garo wallbox Glb Firmware
Garo wallbox Glb
Garo wallbox Gtb
Garo wallbox Gtc Firmware
Garo wallbox Gtb Firmware
Garo
References (MISC) https://www.garo.se/ - (MISC) https://www.garo.se/ - Product
References (MISC) https://github.com/Yof3ng/IoT/blob/master/Garo/CVE-2023-30399.md - (MISC) https://github.com/Yof3ng/IoT/blob/master/Garo/CVE-2023-30399.md - Exploit, Third Party Advisory
References (MISC) http://garocharging.com/glb-wallbox/ - (MISC) http://garocharging.com/glb-wallbox/ - Product
CWE CWE-732
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.1
CPE cpe:2.3:h:garo:wallbox_gtb:-:*:*:*:*:*:*:*
cpe:2.3:o:garo:wallbox_glb_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:garo:wallbox_gtb_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:garo:wallbox_gtc_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:garo:wallbox_glb:-:*:*:*:*:*:*:*
cpe:2.3:h:garo:wallbox_gtc:-:*:*:*:*:*:*:*

04 May 2023, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-05-04 21:15

Updated : 2025-01-29 20:15


NVD link : CVE-2023-30399

Mitre link : CVE-2023-30399


JSON object : View

Products Affected

garo

  • wallbox_glb
  • wallbox_gtc
  • wallbox_gtb
  • wallbox_gtc_firmware
  • wallbox_glb_firmware
  • wallbox_gtb_firmware
CWE
CWE-732

Incorrect Permission Assignment for Critical Resource