PT-2025-6855 · Unknown · Pihome-Shc Pihome

Jelle Janssens

·

Published

2025-02-12

·

Updated

2025-02-12

·

CVE-2025-1214

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions pihome-shc PiHome version 2.0
Description A critical vulnerability has been found in pihome-shc PiHome, affecting an unknown part of the file /user accounts.php?uid of the component Role-Based Access Control. The manipulation leads to missing authorization, and it is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Recommendations For pihome-shc PiHome version 2.0, as a temporary workaround, consider restricting access to the /user accounts.php?uid endpoint until a patch is available. Additionally, review the Role-Based Access Control component to ensure proper authorization mechanisms are in place. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Incorrect Authorization

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-1214

Affected Products

Pihome-Shc Pihome