CVE-2022-36228

Nokelock Smart padlock O1 Version 5.3.0 is vulnerable to Insecure Permissions. By sending a request, you can add any device and set the device password in the Nokelock app.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:janusintl:noke_standard_smart_padlock_firmware:5.3.0:*:*:*:*:*:*:*
cpe:2.3:h:janusintl:noke_standard_smart_padlock:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:janusintl:noke_hd_smart_padlock_firmware:5.3.0:*:*:*:*:*:*:*
cpe:2.3:h:janusintl:noke_hd_smart_padlock:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:janusintl:noke_hd\+_smart_padlock_firmware:5.3.0:*:*:*:*:*:*:*
cpe:2.3:h:janusintl:noke_hd\+_smart_padlock:-:*:*:*:*:*:*:*

History

21 Nov 2024, 07:12

Type Values Removed Values Added
References () https://gist.github.com/YTrick/59c06611052d3fdae034e7087293bbc0 - Third Party Advisory () https://gist.github.com/YTrick/59c06611052d3fdae034e7087293bbc0 - Third Party Advisory

12 Oct 2023, 18:37

Type Values Removed Values Added
First Time Janusintl noke Hd Smart Padlock Firmware
Janusintl
Janusintl noke Standard Smart Padlock
Janusintl noke Standard Smart Padlock Firmware
Janusintl noke Hd Smart Padlock
Janusintl noke Hd\+ Smart Padlock
Janusintl noke Hd\+ Smart Padlock Firmware
References (MISC) https://gist.github.com/YTrick/59c06611052d3fdae034e7087293bbc0 - (MISC) https://gist.github.com/YTrick/59c06611052d3fdae034e7087293bbc0 - Third Party Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
CWE CWE-862
CPE cpe:2.3:o:janusintl:noke_standard_smart_padlock_firmware:5.3.0:*:*:*:*:*:*:*
cpe:2.3:h:janusintl:noke_hd\+_smart_padlock:-:*:*:*:*:*:*:*
cpe:2.3:h:janusintl:noke_hd_smart_padlock:-:*:*:*:*:*:*:*
cpe:2.3:h:janusintl:noke_standard_smart_padlock:-:*:*:*:*:*:*:*
cpe:2.3:o:janusintl:noke_hd\+_smart_padlock_firmware:5.3.0:*:*:*:*:*:*:*
cpe:2.3:o:janusintl:noke_hd_smart_padlock_firmware:5.3.0:*:*:*:*:*:*:*

09 Oct 2023, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-10-09 21:15

Updated : 2024-11-21 07:12


NVD link : CVE-2022-36228

Mitre link : CVE-2022-36228

CVE.ORG link : CVE-2022-36228


JSON object : View

Products Affected

janusintl

  • noke_hd_smart_padlock
  • noke_hd\+_smart_padlock
  • noke_hd_smart_padlock_firmware
  • noke_standard_smart_padlock
  • noke_hd\+_smart_padlock_firmware
  • noke_standard_smart_padlock_firmware
CWE
CWE-862

Missing Authorization