CVE-2017-7728
9.8
CRITICAL · CVSS 3.1 · EPSS 3.5% (pctl 89)
In your normal cycle
Critical by CVSS (9.8), but no sign of active exploitation.
Description
On iSmartAlarm cube devices, there is authentication bypass leading to remote execution of commands (e.g., setting the alarm on/off), related to incorrect cryptography.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 3.49% — more likely to be exploited than 89% of all CVEs |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2017-07-11 |
| Last modified | 2026-06-17 |
Affected (2)
| Vendor | Product |
|---|---|
| ismartalarm | cubeone |
| ismartalarm | cubeone firmware |
References
→ the Explorer · watch your stack · NVD