CVE-2023-0333

Unauthorized Access Vulnerability in IoT Device Management Portal

Vulnerability

Improper access control in the IoT Device Management Portal allows unauthorized users to access sensitive device configurations and administrative features without proper authentication.

Vulnerability Description

The portal lacked sufficient authorization checks for certain critical API endpoints. As a result, attackers could bypass authentication and directly interact with privileged functionality, potentially leading to device manipulation, data exposure, or denial of service.

CVE-ID

CVE-2023-0333

Vendor

CERT-In

Product

IoT Device Management Web Interface

Disclosure Timeline

Credit

Shakir Zari

🔗 View Official Advisory