CVE-2024-46040: Medium severity iot haat smart plug vulnerability
IoT Haat Smart Plug IH-IN-16A-S IH-IN-16A-S v5.16.1 suffers from Insufficient Session Expiration. The lack of validation of the authentication token at the IoT Haat during the Access Point Pairing mode leads the attacker to replay the Wi-Fi packets and forcefully turn off the access point after the authentication token has expired.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-46040?
CVE-2024-46040 is classified as a medium severity vulnerability due to insufficient session expiration in IoT Haat Smart Plug.
How do I fix CVE-2024-46040?
To fix CVE-2024-46040, ensure that the authentication token is properly validated and implement session expiration controls during Access Point Pairing.
Which devices are affected by CVE-2024-46040?
CVE-2024-46040 affects the IoT Haat Smart Plug IH-IN-16A-S running v5.16.1.
What is the impact of CVE-2024-46040?
The impact of CVE-2024-46040 allows an attacker to replay Wi-Fi packets, potentially leading to unauthorized control of the Smart Plug.
Is CVE-2024-46040 under active exploitation?
As of now, there have been no confirmed reports indicating that CVE-2024-46040 is actively being exploited in the wild.