PT-2025-50239 · Commax · Commax Smart Home System

Published

2025-12-09

·

Updated

2025-12-10

·

CVE-2021-47709

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions COMMAX Smart Home System (affected versions not specified)
Description An unauthenticated attacker can alter configurations and disrupt service. This is achieved by sending a crafted request to the setconf API endpoint. An attacker can initiate a denial-of-service by submitting a malformed request to the setconf endpoint.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Missing Authentication

Weakness Enumeration

Related Identifiers

CVE-2021-47709

Affected Products

Commax Smart Home System