CVE-2022-31277: High severity mi xiaomi lamp 1 firmware vulnerability
Published Jun 16, 2022
·Updated
Xiaomi Lamp 1 v2.0.40066 was discovered to be vulnerable to replay attacks. This allows attackers to to bypass the expected access restrictions and gain control of the switch and other functions via a crafted POST request.
Affected Software
2 affected components
Mi Xiaomi Lamp 1 Firmware=2.0.4_0066
Mi Xiaomi Lamp 1
Event History
Jun 16, 2022
CVE Published
via MITRE·02:53 PM
Data Sourced
via MITRE·02:53 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2022-31277.
2
What is the severity of CVE-2022-31277?
The severity of CVE-2022-31277 is high with a CVSS score of 8.8.
3
What is the affected software?
The affected software is Xiaomi Lamp 1 with firmware version 2.0.4_0066.
4
How can attackers exploit CVE-2022-31277?
Attackers can exploit CVE-2022-31277 by performing replay attacks using a crafted POST request.
5
Is there a fix available for CVE-2022-31277?
There is currently no known fix available for CVE-2022-31277. It is recommended to contact the vendor for further information.