Entreprise d'experts en Sécurité Informatique : Audits et conseils en cybersécurité
Entreprise française de cybersécurité depuis 2004
☎ 03 60 47 09 81 - info@securiteinfo.com


CVE-2023-42470

Description

The Imou Life com.mm.android.smartlifeiot application through 6.8.0 for Android allows Remote Code Execution via a crafted intent to an exported component. This relates to the com.mm.android.easy4ip.MainActivity activity. JavaScript execution is enabled in the WebView, and direct web content loading occurs.

POC

Reference

- https://github.com/actuator/cve/blob/main/CVE-2023-42470

- https://github.com/actuator/imou/blob/main/imou-life-6.8.0.md

- https://github.com/actuator/imou/blob/main/poc.apk

Github

- https://github.com/actuator/cve

- https://github.com/actuator/imou

- https://github.com/nomi-sec/PoC-in-GitHub