Owllabs develops Meeting Owl Pro, a conference-room camera and microphone system, with identified vulnerabilities centered on authentication and credential management in the device firmware. The observed weakness classes—hard-coded credentials, improper authentication mechanisms, inadequate encryption strength, and missing authentication for critical functions—reflect common embedded-device challenges around access control and secure initialization. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Owllabs over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-31462HIGH Owl Labs Meeting Owl 5.2.0.15 allows attackers to control the device via a backdoor password (derived from the serial number) that can be found in Bluetooth broadcast data. | Jun 2, 2022 | 8.8 | 28 | NO | NO |
CVE-2022-31460HIGH Owl Labs Meeting Owl 5.2.0.15 allows attackers to activate Tethering Mode with hard-coded hoothoot credentials via a certain c 150 value. | Jun 2, 2022 | 7.4 | 26 | NO | NO |
CVE-2022-31463HIGH Owl Labs Meeting Owl 5.2.0.15 does not require a password for Bluetooth commands, because only client-side authentication is used. | Jun 2, 2022 | 7.1 | 23 | NO | NO |
CVE-2022-31461MEDIUM Owl Labs Meeting Owl 5.2.0.15 allows attackers to deactivate the passcode protection mechanism via a certain c 11 message. | Jun 2, 2022 | 6.5 | 23 | NO | NO |
CVE-2022-31459MEDIUM Owl Labs Meeting Owl 5.2.0.15 allows attackers to retrieve the passcode hash via a certain c 10 value over Bluetooth. | Jun 2, 2022 | 6.5 | 23 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Owllabs.
Media articles that mention a CVE ID that affects a product developed by Owllabs — matched by CVE ID, not by vendor name.