Default Credentials Vulnerability in MR-GM2 and MR-GM3 Firmware by MR-Labs
CVE-2023-45194

4.3MEDIUM

What is CVE-2023-45194?

The presence of default credentials in MR-GM2 firmware versions up to 3.00.03 and MR-GM3 firmware versions up to 1.03.45 poses a significant security risk. This vulnerability enables a network-adjacent attacker to exploit the default pre-shared key, allowing interception of wireless LAN communications. To mitigate this threat, it is crucial for users to change default credentials immediately after deployment.

Affected Version(s)

MR-GM2 firmware Ver. 3.00.03 and earlier

MR-GM3 (-D/-K/-S/-DK/-DKS/-M/-W) firmware Ver. 1.03.45 and earlier

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.