CVE-2023-45194

Use of default credentials vulnerability in MR-GM2 firmware Ver. 3.00.03 and earlier, and MR-GM3 (-D/-K/-S/-DK/-DKS/-M/-W) firmware Ver. 1.03.45 and earlier allows a network-adjacent unauthenticated attacker to intercept wireless LAN communication, when the affected product performs the communication without changing the pre-shared key from the factory-default configuration.
References
Link Resource
https://jvn.jp/en/vu/JVNVU99039725/ Third Party Advisory
https://www.mrl.co.jp/20231005_security/ Patch Vendor Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:mrl:mr-gm3-d_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mrl:mr-gm3-d:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:mrl:mr-gm3-k_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mrl:mr-gm3-k:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:mrl:mr-gm3-s_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mrl:mr-gm3-s:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:mrl:mr-gm3-dks_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mrl:mr-gm3-dks:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:mrl:mr-gm3-m_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mrl:mr-gm3-m:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:mrl:mr-gm2_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mrl:mr-gm2:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:mrl:mr-gm3-w_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mrl:mr-gm3-w:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2023-10-11 01:15

Updated : 2023-10-31 18:08


NVD link : CVE-2023-45194

Mitre link : CVE-2023-45194

CVE.ORG link : CVE-2023-45194


JSON object : View

Products Affected

mrl

  • mr-gm3-s_firmware
  • mr-gm3-d_firmware
  • mr-gm3-w_firmware
  • mr-gm3-w
  • mr-gm3-d
  • mr-gm2_firmware
  • mr-gm3-dks
  • mr-gm2
  • mr-gm3-k_firmware
  • mr-gm3-m_firmware
  • mr-gm3-s
  • mr-gm3-dks_firmware
  • mr-gm3-k
  • mr-gm3-m
CWE
CWE-798

Use of Hard-coded Credentials