An issue was discovered on certain Nuki Home Solutions devices. The code used to parse the JSON objects received from the WebSocket service provided by the device leads to a stack buffer overflow. An attacker would be able to exploit this to gain arbitrary code execution on a KeyTurner device. This affects Nuki Smart Lock 3.0 before 3.3.5 and 2.0 before 2.12.4, as well as Nuki Bridge v1 before 1.22.0 and v2 before 2.13.2.
Metrics
Affected Vendors & Products
References
History
No history.

Status: PUBLISHED
Assigner: mitre
Published: 2024-05-09T19:33:56.851Z
Updated: 2025-02-13T15:46:24.289Z
Reserved: 2022-06-06T00:00:00.000Z
Link: CVE-2022-32504

Updated: 2024-08-03T07:46:43.568Z

Status : Awaiting Analysis
Published: 2024-05-14T10:43:41.203
Modified: 2024-11-21T07:06:30.037
Link: CVE-2022-32504

No data.