CVE-2018-19982 describes a vulnerability in KT MC01507L Z-Wave S0 devices and their associated firmware, stemming from the lack of HPKP implementation. This medium-severity vulnerability (CVSS 5.3) allows an attacker on the same local network to intercept and sniff cleartext communications between the server and the Z-Wave controller, potentially gaining control over connected devices and even obtaining the Z-Wave network key. Exploitation requires an attacker to be on the same local network and use an IP changer to redirect traffic to a proxy server. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:powermanager:kt_mc01507l_z-wave_s0_firmware:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.