vendor:
Blink1Control2
by:
p1ckzi
7.5
CVSS
HIGH
Weak Password Encryption
327
CWE
Product Name: Blink1Control2
Affected Version From: blink1control2 <= 2.2.7
Affected Version To: blink1control2 <= 2.2.7
Patch Exists: YES
Related CWE: CVE-2022-35513
CPE: 2.2.2007
Platforms Tested: Ubuntu Linux 20.04, Windows 10, Windows 11
2022
Blink1Control2 2.2.7 – Weak Password Encryption
The blink1control2 app (versions <= 2.2.7) utilises an insecure method of password storage which can be found by accessing the /blink1/input url of the api server. Password ciphertext for skype logins and email are listed and can be decrypted.
Mitigation:
Ensure that passwords are stored securely using a secure encryption algorithm.