CVE-2023-45194: Mrl Mr-GM2 Firmware
Medium severity, CVSS 4.3. EPSS: 0.2% chance of exploitation in the next 30 days.
Use of default credentials vulnerability in MR-GM2 firmware Ver. 3.00.03 and earlier, and MR-GM3 (-D/-K/-S/-DK/-DKS/-M/-W) firmware Ver. 1.03.45 and earlier allows a network-adjacent unauthenticated attacker to intercept wireless LAN communication, when the affected product performs the communication without changing the pre-shared key from the factory-default configuration.
Affected products
- Mrl Mr-GM2 Firmware: before 3.01.00 (fixed in 3.01.00)
- Mrl Mr-GM3-D Firmware: before 1.04.00 (fixed in 1.04.00)
- Mrl Mr-GM3-Dks Firmware: before 1.04.00 (fixed in 1.04.00)
- Mrl Mr-GM3-K Firmware: before 1.04.00 (fixed in 1.04.00)
- Mrl Mr-GM3-M Firmware: before 1.04.00 (fixed in 1.04.00)
- Mrl Mr-GM3-S Firmware: before 1.04.00 (fixed in 1.04.00)
- Mrl Mr-GM3-W Firmware: before 1.04.00 (fixed in 1.04.00)
Published 2023-10-11. Last modified 2026-06-17.