Uncensored message display via client-side filter bypass
Published Jun 28, 2023 · Updated Nov 27, 2024
Missing authentication in 7-Eleven LED Message Cup 1.3.1 allows physically proximate attackers to display uncensored text over BLE. The Hello Cup Android app applies its regex wordlist only before transmission, while the cup accepts BLE messages from a modified app without enforcing the filter. BLE proximity and a modified client are required; the demonstrated consequence is unauthorized display content rather than data disclosure or service interruption.
Summary
What happened
Missing authentication in 7-Eleven LED Message Cup 1.3.1 allows physically proximate attackers to display uncensored text over BLE. The Hello Cup Android app applies its regex wordlist only before transmission, while the cup accepts BLE messages from a modified app without enforcing the filter. BLE proximity and a modified client are required; the demonstrated consequence is unauthorized display content rather than data disclosure or service interruption.
The record
- CVE
- CVE-2023-34761
- Published
- Jun 28, 2023
- Updated
- Nov 27, 2024
- Vendor
- 7-Eleven, Inc.
- Product
- 7-Eleven LED Message Cup
- Classifications
- CWE-306, T1491.002
- Attack vector
- adjacent
- Privileges
- unauthenticated
Timeline
How it unfolded
- Jun 28, 2023CVE publishedPublication date reported by the CVE source.
- Nov 27, 2024Record updatedLatest update available in the CVE record.
Exploitability
Present is not the same as exploitable
Compare your product and version with the public record. A matching version still requires validation against your environment.
Is a vulnerable build present?
Compare these published version ranges with your installed build and any vendor patches.
- Affected versionversion=1.3.1
What conditions does exploitation require?
What is affected?
Published CVSS scores
CVSS describes severity. EPSS estimates exploitation probability.
Attacks
What attackers are doing with it
Daily unique IPs observed by Shadowserver honeypots for known exploited vulnerabilities (KEVs). Missing observations do not establish an absence of attacks.
Weakness, pattern, technique
Public exploit references
- 7-Eleven Bluetooth Smart Cup Jailbreakfunctional · demonstrated
Labels summarize the accepted research assessment. They do not indicate a test against your environment.
Technologies
Your stack
See the directory against your own environment.
Your stack
Check the software in your environment
Book a demo to see how Hinoki identifies affected software and validates exploitability in your environment.
Book a demo