CVE-2023-30399 describes a critical vulnerability in GARO Wallbox GLB/GTB/GTC devices prior to v189, where insecure permissions on the settings page allow for a Man-in-the-Middle (MitM) attack. This high-severity vulnerability (CVSS 8.1) enables attackers to redirect users to malicious update packages, potentially leading to full compromise (C, I, A: High) without user interaction, though it requires high attack complexity. Currently, there is no evidence of active exploitation, public exploit code, or significant community discussion, indicating a low immediate threat despite its high potential impact.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 189CPE matchmatch criteria | cpe:2.3:o:garo:wallbox_glb_firmware:*:*:*:*:*:*:*:* | ||
<= 189CPE matchmatch criteria | cpe:2.3:o:garo:wallbox_gtb_firmware:*:*:*:*:*:*:*:* | ||
<= 189CPE matchmatch criteria | cpe:2.3:o:garo:wallbox_gtc_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.