CVE-2019-5635
HIGHHickory Smart Ethernet Bridge - Cleartext Transmission of Sensitive Information via MQTT
Title source: llmDescription
A cleartext transmission of sensitive information vulnerability is present in Hickory Smart Ethernet Bridge from Belwith Products, LLC. Captured data reveals that the Hickory Smart Ethernet Bridge device communicates over the network to an MQTT broker without using encryption. This exposed the default username and password used to authenticate to the MQTT broker. This issue affects Hickory Smart Ethernet Bridge, model number H077646. The firmware does not appear to contain versioning information.
References (2)
Core 2
Core References
Third Party Advisory x_refsource_misc
https://blog.rapid7.com/2019/08/01/r7-2019-18-multiple-hickory-smart-lock-vulnerabilities/
Product x_refsource_misc
https://hickoryhardware.com/products/hickory-smart-ethernet-bridge?variant=20882150228086
Scores
CVSS v3
7.5
EPSS
0.0037
EPSS Percentile
28.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Details
CWE
CWE-319
Status
published
Products (1)
belwith-keeler/hickory_smart_ethernet_bridge_firmware
Published
Aug 22, 2019
Tracked Since
Feb 18, 2026