Medium severity5.4NVD Advisory· Published Jan 23, 2024· Updated Jun 17, 2026
CVE-2023-42143
CVE-2023-42143
Description
Missing Integrity Check in Shelly TRV 20220811-152343/v2.1.8@5afc928c allows malicious users to create a backdoor by redirecting the device to an attacker-controlled machine which serves the manipulated firmware file. The device is updated with the manipulated firmware.
Affected products
3- cpe:2.3:o:shelly:trv_firmware:2.1.8:*:*:*:*:*:*:*
- Shelly/TRVdescription
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.