VYPR
Unrated severityNVD Advisory· Published Feb 4, 2022· Updated Apr 15, 2025

CVE-2021-21959

CVE-2021-21959

Description

A misconfiguration exists in the MQTTS functionality of Sealevel Systems, Inc. SeaConnect 370W v1.3.34. This misconfiguration significantly simplifies a man-in-the-middle attack, which directly leads to control of device functionality.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Sealevel SeaConnect 370W v1.3.34 MQTTS ignores certificate validation, enabling simple man-in-the-middle attacks that compromise device control.

Vulnerability

The SeaConnect 370W (firmware v1.3.34) fails to validate TLS server certificates when establishing MQTTS connections. In the function GetConnected (offset 0x10446), the call to NetworkConnectTLS at offset 0x7A accepts a certificate_filename parameter; when set to NULL, no certificate validation is performed [1]. This misconfiguration is tracked as CWE-295 (Improper Certificate Validation).

Exploitation

An attacker with network access to the device can perform a man-in-the-middle attack by intercepting the MQTTS handshake and presenting a self-signed or forged certificate. The device will accept the connection without any warning, allowing the attacker to read and inject MQTT messages. No authentication or user interaction is required, though the attacker must be on the same network segment or be able to route traffic through them.

Impact

Successful exploitation gives the attacker the ability to fully control the device's functionality, including digital and analog I/O, relays, and the 1-wire bus. The CIA impact is: confidentiality low (exposure of MQTT payloads), integrity high (modification of commands), availability high (disruption of operations). The CVSSv3 score is 7.7 (AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H).

Mitigation

As of the publication date (February 2022), no firmware update or workaround has been released by Sealevel Systems to address this vulnerability. Users should monitor the vendor's advisory and restrict network access to the device to trusted segments only until a patch is available.

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.