PT-2020-16661 · Magic Home · Magic Home Pro

Victor Hanna

·

Published

2020-12-17

·

Updated

2021-03-23

·

CVE-2020-27199

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Magic Home Pro version 1.5.1
Description The Magic Home Pro application allows authentication bypass due to its simple username and password authentication function. An attacker can use enumeration to forge a user-specific token without needing the correct password, thereby gaining access to the mobile application as the victim user.
Recommendations For Magic Home Pro version 1.5.1, consider disabling the authentication function temporarily until a patch is available to prevent exploitation. Restrict access to sensitive features of the application to minimize the risk of unauthorized access. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-27199

Affected Products

Magic Home Pro