漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Missing Firmware Authenticity Checks in Solax Power Pocket WiFi models
Vulnerability Description
The firmware update functionality does not verify the authenticity of the supplied firmware update files. This allows attackers to flash malicious firmware update files on the device. Initial analysis of the firmware update functionality does not show any cryptographic checks (e.g. digital signature checks) on the supplied firmware update files. Furthermore, ESP32 security features such as secure boot are not used.
CVSS Information
N/A
Vulnerability Type
下载代码缺少完整性检查
Vulnerability Title
SolaX Power Pocket 安全漏洞
Vulnerability Description
SolaX Power Pocket是中国艾罗能源(SolaX)公司的一个监控数据采集工具。 SolaX Power Pocket存在安全漏洞,该漏洞源于固件更新功能未验证所提供固件更新文件的真实性,可能导致攻击者在设备上刷入恶意固件更新文件。
CVSS Information
N/A
Vulnerability Type
N/A