{"id":"CVE-2022-35513","aliases":["GHSA-jqhq-pfg3-fg5p"],"url":"https://o3.security/vulnerability/CVE-2022-35513","summary":"Blink1Control2 uses weak password encryption","details":"The Blink1Control2 application <= 2.2.7 uses weak password encryption and an insecure method of storage. Version 2.2.9 fixes the issue.","published":"2022-09-07T13:54:18Z","modified":"2026-08-12T03:51:22.890983692Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":3,"affectedPackages":[{"ecosystem":"npm","name":"Blink1Control2","fixedVersion":"2.2.9"}],"fix":{"url":"https://github.com/todbot/Blink1Control2/commit/74827462aba3a26d7bf157522f69eec999d7ba85","label":"todbot/Blink1Control2@7482746"},"references":[{"type":"WEB","url":"http://packetstormsecurity.com/files/168428/Blink1Control2-2.2.7-Weak-Password-Encryption.html"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/35xxx/CVE-2022-35513.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-35513"},{"type":"PACKAGE","url":"https://github.com/p1ckzi/CVE-2022-35513"},{"type":"PACKAGE","url":"https://github.com/todbot/Blink1Control2/releases"},{"type":"WEB","url":"https://github.com/todbot/Blink1Control2/issues/175"},{"type":"WEB","url":"https://github.com/todbot/Blink1Control2/commit/74827462aba3a26d7bf157522f69eec999d7ba85"},{"type":"WEB","url":"https://github.com/todbot/Blink1Control2/commit/cd9229ef9131bc663f714150c9f8d5cbf818d620"},{"type":"WEB","url":"https://github.com/todbot/Blink1Control2/commit/efe174823f67bbdcee8863e02df67a130f132075"},{"type":"WEB","url":"https://github.com/todbot/Blink1Control2/commit/f595d782d2356878188fed423a7dcb84ee8fee9d"},{"type":"PACKAGE","url":"https://github.com/todbot/Blink1Control2"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:22.890983692Z"}}