Insecure permissions in the settings page of GARO Wallbox GLB/GTB/GTC before v189 allows attackers to redirect users to a crafted update package link via a man-in-the-middle attack.
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
Link | Tags |
---|---|
http://garocharging.com/glb-wallbox/ | product |
https://www.garo.se/ | product |
https://github.com/Yof3ng/IoT/blob/master/Garo/CVE-2023-30399.md | third party advisory exploit |