CVE-2018-20100

CRITICAL

August Connect - Info Disclosure

Title source: llm
STIX 2.1

Description

An issue was discovered on August Connect devices. Insecure data transfer between the August app and August Connect during configuration allows attackers to discover home Wi-Fi credentials. This data transfer uses an unencrypted access point for these credentials, and passes them in an HTTP POST, using the AugustWifiDevice class, with data encrypted with a fixed key found obfuscated in the app.

Scores

CVSS v3 9.8
EPSS 0.0016
EPSS Percentile 36.6%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-311
Status published
Products (2)
august/august_connect
august/august_connect_firmware
Published Jan 02, 2019
Tracked Since Feb 18, 2026