PT-2026-22357 · Homey Bnb · Homey Bnb
Published
2026-02-27
·
Updated
2026-02-27
·
CVE-2019-25489
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Homey BNB version 4
Description
The software contains a SQL injection issue that allows unauthenticated attackers to manipulate database queries. Attackers can inject SQL code through the
hosting id parameter. Malicious hosting id values can be sent in GET requests to the /rooms/ajax refresh subtotal API endpoint to extract sensitive database information or cause a denial of service.Recommendations
Apply a fix to sanitize the
hosting id parameter to prevent SQL injection attacks.Exploit
Fix
DoS
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Homey Bnb