Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CVE-2023-2626

7.5 · HIGH
Published Jul 25, 2023 google CWE-287 EPSS 0.11% (2th pctl)

Overview

CVE-2023-2626 is a high-severity vulnerability affecting google nest_hub_max_firmware. It was published on July 25, 2023 and has a CVSS 3.1 base score of 7.5 (HIGH).

This vulnerability has a CVSS 3.1 base score of 7.5, rated HIGH. It requires local or adjacent network access to exploit. No authentication or special privileges are required for exploitation.

Technical Description

There exists an authentication bypass vulnerability in OpenThread border router devices and implementations. This issue allows unauthenticated nodes to craft radio frames using “Key ID Mode 2”: a special mode using a static encryption key to bypass security checks, resulting in arbitrary IP packets being allowed on the Thread network.

This provides a pathway for an attacker to send/receive arbitrary IPv6 packets to devices on the LAN, potentially exploiting them if they lack additional authentication or contain any network vulnerabilities that would normally be mitigated by the home router’s NAT firewall. Effected devices have been mitigated through an automatic update beyond the affected range.

Remediation

Check the references section for vendor advisories and patches from google. Update nest_hub_max_firmware to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

Affected Products

Vendor Product Versions Status
google nest_hub_max_firmware >= 10.20221207.2.109, < 10.20221207.2.120 Affected
google nest_hub_firmware >= 10.20221207.2.100038, < 10.20221207.2.100042 Affected
google wifi_firmware >= 14150.881.7, < 14150.882.9 Affected
google nest_wifi_point_firmware >= 1.56.1, < 1.56.368671 Affected
google nest_wifi_6e_firmware >= 1.59, < 1.63.355999 Affected

Frequently Asked Questions

What is CVE-2023-2626?

CVE-2023-2626 is a high-severity vulnerability affecting google nest_hub_max_firmware. It was published on July 25, 2023 and has a CVSS 3.1 base score of 7.5 (HIGH).

How severe is CVE-2023-2626?

This vulnerability has a CVSS 3.1 base score of 7.5, rated HIGH. It requires local or adjacent network access to exploit. No authentication or special privileges are required for exploitation.

How do I fix or remediate CVE-2023-2626?

Check the references section for vendor advisories and patches from google. Update nest_hub_max_firmware to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

How can CyberStrike help with CVE-2023-2626?

CyberStrike's AI-powered security agents can automatically detect CVE-2023-2626 across your infrastructure using autonomous pentesting, DAST scanning, and HackBrowser. The platform continuously monitors for known vulnerabilities and provides actionable remediation guidance prioritized by real-world exploitability.