AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2022-24188

HIGH · CVSS 7.5 EPSS 0.48%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2022-11-28 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 7.5. See the original NVD description below for full technical details.

CVE
CVE-2022-24188
Severity
HIGH
CVSS
7.5
EPSS
0.48%

Original NVD Description

The /device/signin end-point for the Ourphoto App version 1.4.1 discloses clear-text password information for functionality within the picture frame devices. The deviceVideoCallPassword and mqttPassword are returned in clear-text. The lack of sessions management and presence of insecure direct object references allows to return password information for other end-users devices. Many of the picture frame devices offer video calling, and it is likely this information can be used to abuse that functionality.

Related CVEs

Other vulnerabilities affecting the same vendor(s)