Home

Description

A specially crafted message can be sent to the TTLock App that downgrades the encryption protocol used for communication, and can be utilized to compromise the lock, such as through revealing the unlockKey field.

PUBLISHED Reserved 2023-12-20 | Published 2024-12-19 | Updated 2025-11-04 | Assigner certcc

Problem types

CWE-757: Selection of Less-Secure Algorithm During Negotiation ('Algorithm Downgrade')

Product status

6.4.5 (custom)
affected

References

www.kb.cert.org/vuls/id/949046

alephsecurity.com/2024/03/07/kontrol-lux-lock-2/

cve.org (CVE-2023-7005)

nvd.nist.gov (CVE-2023-7005)

Download JSON