VYPR
Unrated severityNVD Advisory· Published Oct 31, 2023· Updated Sep 5, 2024

lte-pic32-writer's sendto.txt may disclose URL and the API key

CVE-2023-46723

Description

lte-pic32-writer is a writer for PIC32 devices. In versions 0.0.1 and prior, those who use sendto.txt are vulnerable to attackers who known the IMEI reading the sendto.txt. The sendto.txt file can contain the SNS(such as slack and zulip) URL and API key. As of time of publication, a patch is not yet available. As workarounds, avoid using sendto.txt or use .htaccess to block access to sendto.txt.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.