CVE-2023-1083: Welotec TK515L
Critical severity, CVSS 9.8. EPSS: 0.7% chance of exploitation in the next 30 days.
An unauthenticated remote attacker who is aware of a MQTT topic name can send and receive messages, including GET/SET configuration commands, reboot commands and firmware updates.
Affected products
- Welotec TK515L: before v2.3.0.r5542 (fixed in v2.3.0.r5542); before 2.3.0.r5542 (fixed in 2.3.0.r5542)
- Welotec TK515L-W: before v2.3.0.r5542 (fixed in v2.3.0.r5542)
- Welotec TK515L-W Set: before v2.3.0.r5542 (fixed in v2.3.0.r5542)
- Welotec TK515L Set: before v2.3.0.r5542 (fixed in v2.3.0.r5542)
- Welotec TK525L: before v2.3.0.r5542 (fixed in v2.3.0.r5542); before 2.3.0.r5542 (fixed in 2.3.0.r5542)
- Welotec TK525L-W: before v2.3.0.r5542 (fixed in v2.3.0.r5542)
- Welotec TK525L-W Set: before v2.3.0.r5542 (fixed in v2.3.0.r5542)
- Welotec TK525L Set: before v2.3.0.r5542 (fixed in v2.3.0.r5542)
- Welotec TK525U: before v2.3.0.r5542 (fixed in v2.3.0.r5542); before 2.3.0.r5542 (fixed in 2.3.0.r5542)
- Welotec TK525U Set: before v2.3.0.r5542 (fixed in v2.3.0.r5542)
- Welotec TK525W: before v2.3.0.r5542 (fixed in v2.3.0.r5542); before 2.3.0.r5542 (fixed in 2.3.0.r5542)
- Welotec TK525W Set: before v2.3.0.r5542 (fixed in v2.3.0.r5542)
- Welotec TK535L1: before v2.3.0.r5542 (fixed in v2.3.0.r5542); before 2.3.0.r5542 (fixed in 2.3.0.r5542)
- Welotec TK535L1 Set: before v2.3.0.r5542 (fixed in v2.3.0.r5542)
Published 2024-04-09. Last modified 2026-06-17.