CVE-2021-3774 affects Meross Smart Wi-Fi 2 Way Wall Switches (MSS550X) running firmware version 3.1.3 and earlier. During initial setup, these devices create an insecure Wi-Fi Access Point, allowing a remote attacker to intercept the user's Wi-Fi SSID and password via unencrypted HTTP/JSON requests. This vulnerability has a CVSS score of 6.5 (Medium) due to its network attack vector and high confidentiality impact, requiring user interaction to initiate the vulnerable setup process. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 3.1.3CPE matchmatch criteria | cpe:2.3:o:meross:mss550x_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.