CVE-2023-42470 is a critical remote code execution vulnerability affecting the Imou Life Android application (com.mm.android.smartlifeiot) through version 6.8.0. An attacker can exploit this by sending a crafted intent to an exported activity, leveraging enabled JavaScript execution within a WebView that directly loads web content. With a CVSS score of 9.8 (Critical), this vulnerability allows for complete compromise of confidentiality, integrity, and availability without user interaction. While no public exploits, Metasploit modules, or significant community discussion have been identified, its high EPSS score and FAUCET Risk Score indicate a substantial threat.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 6.8.0CPE matchmatch criteria | cpe:2.3:a:imoulife:life:*:*:*:*:*:android:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.