← Back to CVE List

CVE-2022-32510

Published: 2024-05-14T10:43Z
Last Modified: 2024-11-21T07:06Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
An issue was discovered on certain Nuki Home Solutions devices. The HTTP API exposed by a Bridge used an unencrypted channel to provide an administrative interface. A token can be easily eavesdropped by a malicious actor to impersonate a legitimate user and gain access to the full set of API endpoints. This affects Nuki Bridge v1 before 1.22.0 and v2 before 2.13.2. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt