Vulnerability CVE-2023-42470


Published: 2023-09-11

Description:
The Imou Life com.mm.android.smartlifeiot application through 6.8.0 for Android allows Remote Code Execution via a crafted intent to an exported component. This relates to the com.mm.android.easy4ip.MainActivity activity. JavaScript execution is enabled in the WebView, and direct web content loading occurs.

 References:
https://github.com/actuator/imou/blob/main/imou-life-6.8.0.md
https://github.com/actuator/imou/blob/main/poc.apk

Copyright 2026, cxsecurity.com

 

Back to Top