CVE-2018-20100
CRITICALAugust Connect - Unencrypted Wi-Fi Credential Exposure via HTTP POST
Title source: llmDescription
An issue was discovered on August Connect devices. Insecure data transfer between the August app and August Connect during configuration allows attackers to discover home Wi-Fi credentials. This data transfer uses an unencrypted access point for these credentials, and passes them in an HTTP POST, using the AugustWifiDevice class, with data encrypted with a fixed key found obfuscated in the app.
References (1)
Core 1
Core References
Third Party Advisory x_refsource_misc
https://dojo.bullguard.com/dojo-by-bullguard/blog/august-connect/
Scores
CVSS v3
9.8
EPSS
0.0071
EPSS Percentile
48.6%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-311
Status
published
Products (2)
august/august_connect
august/august_connect_firmware
Published
Jan 02, 2019
Tracked Since
Feb 18, 2026