CVE-2023-45194 is a medium-severity vulnerability affecting MR-GM2 (firmware Ver. 3.00.03 and earlier) and MR-GM3 (firmware Ver. 1.03.45 and earlier) devices, stemming from the use of default credentials. A network-adjacent, unauthenticated attacker can exploit this by intercepting wireless LAN communication if the factory-default pre-shared key remains unchanged. The CVSS score is 4.3 (MEDIUM), indicating low attack complexity and no user interaction required, with potential for limited impact on confidentiality (interception of communication). There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.04.00CPE matchmatch criteria | cpe:2.3:o:mrl:mr-gm3-d_firmware:*:*:*:*:*:*:*:* | ||
< 1.04.00CPE matchmatch criteria | cpe:2.3:o:mrl:mr-gm3-k_firmware:*:*:*:*:*:*:*:* | ||
< 1.04.00CPE matchmatch criteria | cpe:2.3:o:mrl:mr-gm3-s_firmware:*:*:*:*:*:*:*:* | ||
< 1.04.00CPE matchmatch criteria | cpe:2.3:o:mrl:mr-gm3-dks_firmware:*:*:*:*:*:*:*:* | ||
< 1.04.00CPE matchmatch criteria | cpe:2.3:o:mrl:mr-gm3-m_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.