Unrated severityNVD Advisory· Published Oct 31, 2023· Updated Sep 5, 2024
lte-pic32-writer's sendto.txt may disclose URL and the API key
CVE-2023-46723
Description
lte-pic32-writer is a writer for PIC32 devices. In versions 0.0.1 and prior, those who use sendto.txt are vulnerable to attackers who known the IMEI reading the sendto.txt. The sendto.txt file can contain the SNS(such as slack and zulip) URL and API key. As of time of publication, a patch is not yet available. As workarounds, avoid using sendto.txt or use .htaccess to block access to sendto.txt.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2<=0.0.1+ 1 more
- (no CPE)range: <=0.0.1
- (no CPE)range: <= 0.0.1
Patches
Vulnerability mechanics
References
1- github.com/paijp/lte-pic32-writer/security/advisories/GHSA-9qgg-ph2v-v4mhmitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.