CVE-2023-46889

MEDIUM
Published Jan 23, 2024 Modified Jun 17, 2025 CWE-319

Description

Meross MSH30Q 4.5.23 is vulnerable to Cleartext Transmission of Sensitive Information. During the device setup phase, the MSH30Q creates an unprotected Wi-Fi access point. In this phase, MSH30Q needs to connect to the Internet through a Wi-Fi router. This is why MSH30Q asks for the Wi-Fi network name (SSID) and the Wi-Fi network password. When the user enters the password, the transmission of the Wi-Fi password and name between the MSH30Q and mobile application is observed in the Wi-Fi network. Although the Wi-Fi password is encrypted, a part of the decryption algorithm is public so we complemented the missing parts to decrypt it.

Is your site exposed to CVE-2023-46889?

Run a free security scan — no signup, results in seconds.

CVSS v3.1 Score

5.7
MEDIUM
CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

Weakness Type (CWE)

CWE-319 CWE-319

Affected Products

Vendor Product
meross msh30q_firmware
meross msh30q

References

Frequently Asked Questions

What is CVE-2023-46889? +
Meross MSH30Q 4.5.23 is vulnerable to Cleartext Transmission of Sensitive Information. During the device setup phase, the MSH30Q creates an unprotected Wi-Fi access point. In this phase, MSH30Q needs to connect to the Internet through a Wi-Fi router. This is why MSH30Q asks for the Wi-Fi network name (SSID) and the Wi-Fi network password. When the user enters the password, the transmission of the Wi-Fi password and name between the MSH30Q and mobile application is observed in the Wi-Fi network. Although the Wi-Fi password is encrypted, a part of the decryption algorithm is public so we complemented the missing parts to decrypt it. It has a CVSS v3.1 base score of 5.7 (MEDIUM).
How severe is CVE-2023-46889? +
CVE-2023-46889 has a CVSS v3.1 score of 5.7 out of 10, rated MEDIUM. This is a medium-severity vulnerability that should be remediated as part of regular maintenance.
What products are affected by CVE-2023-46889? +
CVE-2023-46889 affects products from meross, specifically: msh30q, msh30q_firmware. Check the affected products table above for specific version ranges.
How do I check if I'm vulnerable to CVE-2023-46889? +
You can use Secably's free Website Scanner to check your website for known vulnerabilities. For infrastructure scanning, use the Port Scanner to identify exposed services that may be affected. Check the vendor advisories linked above for specific patch and version information.

Related Vulnerabilities

Don't wait for an exploit

Scan your website for vulnerabilities like CVE-2023-46889 — free, no signup required.