High severity7.5NVD Advisory· Published Apr 30, 2020· Updated Jun 17, 2026
CVE-2020-11015
CVE-2020-11015
Description
A vulnerability has been disclosed in thinx-device-api IoT Device Management Server before version 2.5.0. Device MAC address can be spoofed. This means initial registration requests without UDID and spoofed MAC address may pass to create new UDID with same MAC address. Full impact needs to be reviewed further. Applies to all (mostly ESP8266/ESP32) users. This has been fixed in firmware version 2.5.0.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:thinx-device-api_project:thinx-device-api:*:*:*:*:*:node.js:*:*Range: <2.5.0
- Range: <2.5.0
- Range: < 2.5.0
Patches
Vulnerability mechanics
References
1- github.com/suculent/thinx-device-api/security/advisories/GHSA-5x54-39xq-cwvcnvdThird Party Advisory
News mentions
0No linked articles in our index yet.