CVE-2020-14158

CRITICAL

ABUS Secvest Hybrid FUMO50110 Firmware - Authentication Bypass via RF Packet Manipulation

Title source: llm
STIX 2.1

Description

The ABUS Secvest FUMO50110 hybrid module does not have any security mechanism that ensures confidentiality or integrity of RF packets that are exchanged with an alarm panel. This makes it easier to conduct wAppLoxx authentication-bypass attacks.

References (3)

Core 3
Core References
Mailing List, Third Party Advisory mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2020/Jul/36

Scores

CVSS v3 9.1
EPSS 0.0184
EPSS Percentile 76.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Details

CWE
CWE-287
Status published
Products (1)
abus/secvest_hybrid_fumo50110_firmware
Published Jul 30, 2020
Tracked Since Feb 18, 2026