Vulnerabilities > CVE-2020-13425 - Missing Authorization vulnerability in Thetrackr Trackr Firmware 20200506

047910
CVSS 6.8 - MEDIUM
Attack vector
ADJACENT_NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
COMPLETE
low complexity
thetrackr
CWE-862

Summary

TrackR devices through 2020-05-06 allow attackers to trigger the Beep (aka alarm) feature, which will eventually cause a denial of service when battery capacity is exhausted.

Vulnerable Configurations

Part Description Count
OS
Thetrackr
1
Hardware
Thetrackr
1

Common Weakness Enumeration (CWE)