CVE-2022-47070

NVS365 V01 is vulnerable to Incorrect Access Control. After entering a wrong password, the url will be sent to the server twice. In the second package, the server will return the correct password information.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:nvs365:nvs-365-v01_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:nvs365:nvs-365-v01:-:*:*:*:*:*:*:*

History

26 Mar 2025, 16:15

Type Values Removed Values Added
CWE CWE-200

Information

Published : 2023-02-03 21:15

Updated : 2025-03-26 16:15


NVD link : CVE-2022-47070

Mitre link : CVE-2022-47070

CVE.ORG link : CVE-2022-47070


JSON object : View

Products Affected

nvs365

  • nvs-365-v01
  • nvs-365-v01_firmware
CWE
NVD-CWE-Other CWE-200

Exposure of Sensitive Information to an Unauthorized Actor