CVE-2023-2626 (CNNVD-202307-2043)
中文标题:
Google Nest 授权问题漏洞
英文标题:
Authentication Bypass in OpenThread Boarder Router devices
漏洞描述
中文描述:
Google Nest是美国谷歌(Google)公司的一款智能家居产品。 Google Nest存在安全漏洞。该漏洞允许未经身份验证的节点使用“Key ID Mode 2”来伪造无线电帧,这是一种使用静态加密密钥绕过安全检查的特殊模式,从而允许任意 IP 数据包传输到 Thread 网络中。
英文描述:
There exists an authentication bypass vulnerability in OpenThread border router devices and implementations. This issue allows unauthenticated nodes to craft radio frames using “Key ID Mode 2”: a special mode using a static encryption key to bypass security checks, resulting in arbitrary IP packets being allowed on the Thread network. This provides a pathway for an attacker to send/receive arbitrary IPv6 packets to devices on the LAN, potentially exploiting them if they lack additional authentication or contain any network vulnerabilities that would normally be mitigated by the home router’s NAT firewall. Effected devices have been mitigated through an automatic update beyond the affected range.
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| Nest Hub Max | - | < 10.20221207.2.120 | - |
cpe:2.3:a:google:nest_hub_max:*:*:*:*:*:*:*:*
|
|
| Nest Hub (2nd. gen) w/ Sleep Tracking | - | < 10.20221207.2.100042 | - |
cpe:2.3:a:google:nest_hub_(2nd._gen)_w__sleep_tracking:*:*:*:*:*:*:*:*
|
|
| Nest Wifi 6E | - | < 1.63.355999 | - |
cpe:2.3:a:google:nest_wifi_6e:*:*:*:*:*:*:*:*
|
|
| Google Wifi (next gen) | - | < 14150.882.9 | - |
cpe:2.3:a:google:google_wifi_(next_gen):*:*:*:*:*:*:*:*
|
|
| Nest Wifi Point | - | < 1.56.368671 | - |
cpe:2.3:a:google:nest_wifi_point:*:*:*:*:*:*:*:*
|
|
| nest_hub_max_firmware | * | - | - |
cpe:2.3:o:google:nest_hub_max_firmware:*:*:*:*:*:*:*:*
|
|
| nest_hub_firmware | * | - | - |
cpe:2.3:o:google:nest_hub_firmware:*:*:*:*:*:*:*:*
|
|
| wifi_firmware | * | - | - |
cpe:2.3:o:google:wifi_firmware:*:*:*:*:*:*:*:*
|
|
| nest_wifi_point_firmware | * | - | - |
cpe:2.3:o:google:nest_wifi_point_firmware:*:*:*:*:*:*:*:*
|
|
| nest_wifi_6e_firmware | * | - | - |
cpe:2.3:o:google:nest_wifi_6e_firmware:*:*:*:*:*:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
参考链接
cve.org
CVSS评分详情
3.1 (cna)
HIGHCVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2023-2626 |
2025-11-11 15:21:55 | 2025-11-11 07:38:12 |
| NVD | nvd_CVE-2023-2626 |
2025-11-11 14:59:06 | 2025-11-11 07:46:20 |
| CNNVD | cnnvd_CNNVD-202307-2043 |
2025-11-11 15:11:16 | 2025-11-11 07:58:05 |
版本与语言
安全公告
变更历史
查看详细变更
- vulnerability_type: 未提取 -> 授权问题
- cnnvd_id: 未提取 -> CNNVD-202307-2043
- data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
查看详细变更
- affected_products_count: 7 -> 10
- data_sources: ['cve'] -> ['cve', 'nvd']