Description
Meross Smart Wi-Fi 2 Way Wall Switch (MSS550X), on its 3.1.3 version and before, creates an open Wi-Fi Access Point without the required security measures in its initial setup. This could allow a remote attacker to obtain the Wi-Fi SSID as well as the password configured by the user from Meross app via Http/JSON plain request.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
This vulnerability has been solved by Meross in MSS550X version 3.2.3.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-27043 | Meross Smart Wi-Fi 2 Way Wall Switch (MSS550X), on its 3.1.3 version and before, creates an open Wi-Fi Access Point without the required security measures in its initial setup. This could allow a remote attacker to obtain the Wi-Fi SSID as well as the password configured by the user from Meross app via Http/JSON plain request. |
References
History
Wed, 23 Apr 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2025-04-23T19:24:23.318Z
Reserved: 2021-09-06T00:00:00.000Z
Link: CVE-2021-3774
Updated: 2024-08-03T17:09:09.214Z
Status : Modified
Published: 2021-11-05T21:15:08.480
Modified: 2024-11-21T06:22:23.747
Link: CVE-2021-3774
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD