An issue in MOKO TECHNOLOGY LTD MOKOSmart MKGW1 BLE Gateway v.1.1.1 and before allows a remote attacker to escalate privileges via the session management component of the administrative web interface.
https://www.mokosmart.com/wp-content/uploads/2019/10/GS-gateway.pdf