PT-2026-22357 · Homey Bnb · Homey Bnb

Published

2026-02-27

·

Updated

2026-02-27

·

CVE-2019-25489

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions Homey BNB version 4
Description The software contains a SQL injection issue that allows unauthenticated attackers to manipulate database queries. Attackers can inject SQL code through the hosting id parameter. Malicious hosting id values can be sent in GET requests to the /rooms/ajax refresh subtotal API endpoint to extract sensitive database information or cause a denial of service.
Recommendations Apply a fix to sanitize the hosting id parameter to prevent SQL injection attacks.

Exploit

Fix

DoS

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2019-25489

Affected Products

Homey Bnb