vendor:
LA-5570 Wireless Gateway Home Automation Controller
by:
The Security Team
7.5
CVSS
HIGH
Multiple Vulnerabilities
22
CWE
Product Name: LA-5570 Wireless Gateway Home Automation Controller
Affected Version From: 1.0.19_T53
Affected Version To: 1.0.19_T53
Patch Exists: NO
Related CWE: CVE-2023-34723
CPE: a:techview:la-5570:1.0.19_T53
Platforms Tested: MACOS/Linux
2023
Techview LA-5570 Wireless Gateway Home Automation Controller – Multiple Vulnerabilities
The exploit is a directory traversal vulnerability in the TechVIEW LA-5570 home automation controller. By accessing the system.conf file, an attacker can retrieve sensitive information, such as credentials.
Mitigation:
The vendor has not released a patch for this vulnerability. Users are advised to restrict access to the affected device and monitor for any unauthorized access.