Vulnerabilities (CVE)

Filtered by vendor Hopechart
Filtered by product Hqt401
Angry Yack Logo
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-3028 1 Hopechart 2 Hqt401, Hqt401 Firmware 2024-11-21 N/A 8.6 HIGH
Insufficient authentication in the MQTT backend (broker) allows an attacker to access and even manipulate the telemetry data of the entire fleet of vehicles using the HopeChart HQT-401 telematics unit. Other models are possibly affected too. Multiple vulnerabilities were identified: - The MQTT backend does not require authentication, allowing unauthorized connections from an attacker. - The vehicles publish their telemetry data (e.g. GPS Location, speed, odometer, fuel, etc) as mes ...

Show More