aioshelly is vulnerable to Authentication Bypass by Capture-replay
66
Medium Risk
The package fixed a weakness in Shelly RPC authentication handling by correctly processing server authentication challenges (nonce/algorithm) and sequencing the auth counter (nc), then generating auth frames using the current challenge state. It also rejects unsupported auth algorithms, preventing incorrect/stale auth computations that could lead to auth bypass/failure behavior.
You are affected if you are using a version that falls within the vulnerable range.
aioshelly is vulnerable to Authentication Bypass by Capture-replay in versions 2.0.0 - 13.24.0.
Upgrade the aioshelly library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant