CVE-2023-27746
CRITICALBlackVue DR750-2CH LTE 1.012_2022.10.26 - Weak Default Passphrase Brute Force via WPA2 Handshake
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2023-27746. PoCs published by eyJhb.
AI-analyzed exploit summary This repository contains functional exploit code for multiple BlackVue DR750 vulnerabilities, including unauthenticated FOTA (CVE-2023-27748), insecure Wi-Fi password (CVE-2023-27746), and unauthenticated webserver access (CVE-2023-27747). The provided Python scripts demonstrate firmware manipulation, FOTA exploitation, and Wi-Fi password decryption.
Description
BlackVue DR750-2CH LTE v.1.012_2022.10.26 was discovered to contain a weak default passphrase which can be easily cracked via a brute force attack if the WPA2 handshake is intercepted.
Exploits (1)
This repository contains functional exploit code for multiple BlackVue DR750 vulnerabilities, including unauthenticated FOTA (CVE-2023-27748), insecure Wi-Fi password (CVE-2023-27746), and unauthenticated webserver access (CVE-2023-27747). The provided Python scripts demonstrate firmware manipulation, FOTA exploitation, and Wi-Fi password decryption.
References (4)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H