PT-2020-9804 · Homee · Homee Brain Cube V2

Cem Onganer

+1

·

Published

2020-03-20

·

Updated

2021-06-03

·

CVE-2019-16258

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions homee Brain Cube V2 versions 2.23.0 and earlier
Description The issue allows attackers with physical access to gain root access by manipulating the U-Boot environment via the Command Line Interface (CLI) after connecting to the internal UART interface.
Recommendations For homee Brain Cube V2 versions 2.23.0 and earlier, as a temporary workaround, consider restricting physical access to the device to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-16258

Affected Products

Homee Brain Cube V2