CVE-2018-15479 Details
Description
An issue was discovered in myStrom WiFi Switch V1 before 2.66, WiFi Switch V2 before 3.80, WiFi Switch EU before 3.80, WiFi Bulb before 2.58, WiFi LED Strip before 3.80, WiFi Button before 2.73, and WiFi Button Plus before 2.73. Devices did not authenticate themselves to the cloud in device to cloud communication. This lack of device authentication allowed an attacker to impersonate any device by guessing or learning their MAC address.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-287 | Improper Authentication | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| mystrom wifi switch firmware | < 2.66 < 3.80 |
CPE
Remediation
| |
| mystrom wifi switch | v1 v2 |
CPE
Remediation
| |
| mystrom wifi button plus firmware | < 2.73 |
CPE
Remediation
| |
| mystrom wifi button plus | All versions |
CPE
Remediation
| |
| mystrom wifi button firmware | < 2.73 |
CPE
Remediation
| |
| mystrom wifi button | All versions |
CPE
Remediation
| |
| mystrom wifi switch eu firmware | < 3.80 |
CPE
Remediation
| |
| mystrom wifi switch eu | All versions |
CPE
Remediation
| |
| mystrom wifi bulb firmware | < 2.58 |
CPE
Remediation
| |
| mystrom wifi bulb | All versions |
CPE
Remediation
| |
| mystrom wifi led strip firmware | < 3.80 |
CPE
Remediation
| |
| mystrom wifi led strip | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Nov 9, 2018 | Initial Analysis | [email protected] |