Vulnerabilities (CVE)

Filtered by vendor Micodus Subscribe
Filtered by product Mv720 Firmware
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-2141 1 Micodus 2 Mv720, Mv720 Firmware 2022-07-27 N/A 9.8 CRITICAL
SMS-based GPS commands can be executed by MiCODUS MV720 GPS tracker without authentication.
CVE-2022-2107 1 Micodus 2 Mv720, Mv720 Firmware 2022-07-27 N/A 9.8 CRITICAL
The MiCODUS MV720 GPS tracker API server has an authentication mechanism that allows devices to use a hard-coded master password. This may allow an attacker to send SMS commands directly to the GPS tracker as if they were coming from the GPS owner’s mobile number.