CVE-2019-9659

EUVD-2019-19025
The Chuango 433 MHz burglar-alarm product line uses static codes in the RF remote control, allowing an attacker to arm, disarm, or trigger the alarm remotely via replay attacks, as demonstrated by Chuango branded products, and non-Chuango branded products such as the Eminent EM8617 OV2 Wifi Alarm System.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.1 CRITICAL
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 50%
Affected Products (NVD)
VendorProductVersion
chuangowifi_alarm_system_firmware
-
chuangowifi\/cellular_smart_home_system_h4_plus_firmware
-
chuangoawv_plus_wifi_alarm_system_firmware
-
chuangog5w_3g_firmware
-
chuangog5_plus_gsm\/sms\/rfid_touch_alarm_system_firmware
-
chuangog3_gsm\/sms_alarm_system_firmware
-
chuangog5w_3g_firmware
-
chuangob11_dual-network_alarm_system_firmware
-
chuangoa8_pstn_alarm_system_firmware
-
chuangoa11_pstn\/lcd\/rfid_touch_alarm_system_firmware
-
chuangocg-105s_on-site_alarm_system_firmware
-
eminentem8617_ov2_wifi_alarm_system_firmware
-
𝑥
= Vulnerable software versions