vendor:
Shelly PRO 4PM
by:
The Security Team
5.3
CVSS
MEDIUM
Authentication Bypass
287
CWE
Product Name: Shelly PRO 4PM
Affected Version From: Firmware v0.11.0
Affected Version To: Unknown
Patch Exists: NO
Related CWE: CVE-2023-33383
CPE: o:shelly:shelly_pro_4pm_firmware:0.11.0
Platforms Tested: MacOS/Linux
2023
Shelly PRO 4PM v0.11.0 – Authentication Bypass
This exploit allows an attacker to bypass authentication on Shelly PRO 4PM devices with firmware version v0.11.0. By sending specific payloads, the attacker can gain unauthorized access to the device.
Mitigation:
Update the firmware to a version that addresses the authentication bypass vulnerability.