PT-2025-6056 · Unknown · Pihome-Shc Pihome

Jelle Janssens

·

Published

2025-02-10

·

Updated

2025-02-12

·

CVE-2025-1185

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions pihome-shc PiHome version 2.0
Description A critical issue has been found in pihome-shc PiHome, affecting an unknown part of the file "/ajax.php?Ajax=GetModal Sensor Graph". The manipulation leads to SQL injection, and it is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Recommendations For pihome-shc PiHome version 2.0, as a temporary workaround, consider disabling the "/ajax.php?Ajax=GetModal Sensor Graph" endpoint until a patch is available. Restrict access to this endpoint to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Special Elements Injection

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-1185

Affected Products

Pihome-Shc Pihome