The MiCODUS MV720 GPS tracker API server has an authentication mechanism that allows devices to use a hard-coded master password. This may allow an attacker to send SMS commands directly to the GPS tracker as if they were coming from the GPS owner’s mobile number.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://www.cisa.gov/uscert/ics/advisories/icsa-22-200-01 |
![]() ![]() |
History
Wed, 16 Apr 2025 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|

Status: PUBLISHED
Assigner: icscert
Published: 2022-07-20T15:24:35.820Z
Updated: 2025-04-16T16:14:52.167Z
Reserved: 2022-06-16T00:00:00.000Z
Link: CVE-2022-2107

Updated: 2024-08-03T00:24:44.192Z

Status : Modified
Published: 2022-07-20T16:15:08.903
Modified: 2024-11-21T07:00:19.953
Link: CVE-2022-2107

No data.