Vulnerability Details CVE-2023-42470
The Imou Life com.mm.android.smartlifeiot application through 6.8.0 for Android allows Remote Code Execution via a crafted intent to an exported component. This relates to the com.mm.android.easy4ip.MainActivity activity. JavaScript execution is enabled in the WebView, and direct web content loading occurs.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.128
EPSS Ranking 93.8%
CVSS Severity
CVSS v3 Score 9.8
Products affected by CVE-2023-42470
-
cpe:2.3:a:imoulife:life:-
-
cpe:2.3:a:imoulife:life:6.8.0