Vulnerabilities > CVE-2020-13425 - Missing Authorization vulnerability in Thetrackr Trackr Firmware 2.2.5/20200506/5.1.6

047910
CVSS 7.1 - HIGH
Attack vector
ADJACENT_NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
LOW
Availability impact
HIGH
low complexity
thetrackr
CWE-862

Summary

TrackR devices through 2020-05-06 allow attackers to trigger the Beep (aka alarm) feature, which will eventually cause a denial of service when battery capacity is exhausted.

Common Weakness Enumeration (CWE)