aioshelly is vulnerable to Authentication Bypass by Capture-replay
66
Medium Risk
The package fixed a weakness in Shelly RPC authentication handling by correctly processing server authentication challenges (nonce/algorithm) and sequencing the auth counter (nc), then generating auth frames using the current challenge state. It also rejects unsupported auth algorithms, preventing incorrect/stale auth computations that could lead to auth bypass/failure behavior.
You are affected if you are using a version that falls within the vulnerable range.
aioshelly is vulnerable to Authentication Bypass by Capture-replay in versions 2.0.0 - 13.24.0.
Upgrade the aioshelly library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant