CVE-2020-7232
19.01.2020, 20:15
Evoko Home devices 1.31 through 1.37 allow remote attackers to obtain sensitive information (such as usernames and password hashes) via a WebSocket request, as demonstrated by the sockjs/224/uf1psgff/websocket URI at a wss:// URL.Enginsight
Vendor | Product | Version |
---|---|---|
evoko | home | 1.31 ≤ 𝑥 ≤ 1.37 |
𝑥
= Vulnerable software versions