PT-2021-11031 · Homee · Homee Brain Cube

Tobias Jäger

·

Published

2021-05-20

·

Updated

2021-06-03

·

CVE-2020-24395

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: homee Brain Cube v2 versions 2.28.2 through 2.28.4
Description: The issue arises from insufficient validation of the firmware image file in the USB firmware update script, allowing an attacker with physical access to install compromised firmware, which can lead to code execution on the device.
Recommendations: For homee Brain Cube v2 versions 2.28.2 through 2.28.4, as a temporary workaround, consider restricting physical access to the device until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Insufficient Verification of Data Authenticity

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-24395

Affected Products

Homee Brain Cube