CVE-2017-7726 describes an SSL Certificate Validation Vulnerability in iSmartAlarm cube devices, specifically affecting the cubeone and cubeone_firmware. This vulnerability carries a high CVSS score of 7.5, indicating a critical security flaw that can be exploited remotely with low complexity, potentially leading to high integrity impact without requiring user interaction. While there is no evidence of active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered some community discussion and media coverage, including a BleepingComputer article highlighting its potential for home security compromise.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:ismartalarm:cubeone_firmware:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.