Vulnerabilities > Mystrom

DATE CVE VULNERABILITY TITLE RISK
2018-08-30 CVE-2018-15480 Unspecified vulnerability in Mystrom products
An issue was discovered in myStrom WiFi Switch V1 before 2.66, WiFi Switch V2 before 3.80, WiFi Switch EU before 3.80, WiFi Bulb before 2.58, WiFi LED Strip before 3.80, WiFi Button before 2.73, and WiFi Button Plus before 2.73.
network
low complexity
mystrom
8.8
2018-08-30 CVE-2018-15479 Improper Authentication vulnerability in Mystrom products
An issue was discovered in myStrom WiFi Switch V1 before 2.66, WiFi Switch V2 before 3.80, WiFi Switch EU before 3.80, WiFi Bulb before 2.58, WiFi LED Strip before 3.80, WiFi Button before 2.73, and WiFi Button Plus before 2.73.
network
low complexity
mystrom CWE-287
6.5
2018-08-30 CVE-2018-15478 Improper Authentication vulnerability in Mystrom products
An issue was discovered in myStrom WiFi Switch V1 before 2.66, WiFi Switch V2 before 3.80, WiFi Switch EU before 3.80, WiFi Bulb before 2.58, WiFi LED Strip before 3.80, WiFi Button before 2.73, and WiFi Button Plus before 2.73.
network
high complexity
mystrom CWE-287
8.1
2018-08-30 CVE-2018-15477 OS Command Injection vulnerability in Mystrom Wifi Switch Firmware 2.31
myStrom WiFi Switch V1 devices before 2.66 did not sanitize a parameter received from the cloud that was used in an OS command.
network
low complexity
mystrom CWE-78
critical
9.8
2018-08-30 CVE-2018-15476 Improper Certificate Validation vulnerability in Mystrom products
An issue was discovered in myStrom WiFi Switch V1 before 2.66, WiFi Switch V2 before 3.80, WiFi Switch EU before 3.80, WiFi Bulb before 2.58, WiFi LED Strip before 3.80, WiFi Button before 2.73, and WiFi Button Plus before 2.73.
network
high complexity
mystrom CWE-295
8.1