PT-2021-11031 · Homee · Homee Brain Cube
Tobias Jäger
·
Published
2021-05-20
·
Updated
2021-06-03
·
CVE-2020-24395
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
homee Brain Cube v2 versions 2.28.2 through 2.28.4
Description:
The issue arises from insufficient validation of the firmware image file in the USB firmware update script, allowing an attacker with physical access to install compromised firmware, which can lead to code execution on the device.
Recommendations:
For homee Brain Cube v2 versions 2.28.2 through 2.28.4, as a temporary workaround, consider restricting physical access to the device until a patch is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Insufficient Verification of Data Authenticity
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Homee Brain Cube