Show filters
3 Total Results
Displaying 1-3 of 3
Sort by:
Attacker Value
Unknown
CVE-2023-7005
Disclosure Date: December 19, 2024 (last updated December 20, 2024)
A specially crafted message can be sent to the TTLock App that downgrades the encryption protocol used for communication, and can be utilized to compromise the lock, such as through revealing the unlockKey field.
0
Attacker Value
Unknown
CVE-2023-7004
Disclosure Date: March 15, 2024 (last updated February 26, 2025)
The TTLock App does not employ proper verification procedures to ensure that it is communicating with the expected device, allowing for connection to a device that spoofs the MAC address of a lock, which compromises the legitimate locks integrity.
0
Attacker Value
Unknown
CVE-2023-6960
Disclosure Date: March 15, 2024 (last updated April 01, 2024)
TTLock App virtual keys and settings are only deleted client side, and if preserved, can access the lock after intended deletion.
0