An unauthenticated attacker within BLE proximity can remotely connect to a 7-Eleven LED Message Cup, Hello Cup 1.3.1 for Android, and bypass the application's client-side chat censor filter.
References
Link | Resource |
---|---|
https://github.com/actuator/7-Eleven-Bluetooth-Smart-Cup-Jailbreak | Exploit |
https://github.com/actuator/cve/blob/main/CVE-2023-34761 | Third Party Advisory |
Configurations
Configuration 1 (hide)
AND |
|
History
No history.
Information
Published : 2023-06-28 20:15
Updated : 2023-07-06 16:10
NVD link : CVE-2023-34761
Mitre link : CVE-2023-34761
CVE.ORG link : CVE-2023-34761
JSON object : View
Products Affected
7-eleven
- hello_cup
- led_message_cup
CWE