Known Vulnerabilities for products from Homeautomation Project
Listed below are 5 of the newest known vulnerabilities associated with the vendor "Homeautomation Project".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2020-22001 json | HomeAutomation 3.3.2 suffers from an authentication bypass vulnerability when spoofing client IP address using the X-Forwarde... | 9.8 - CRITICAL | 2021-04-27 | 2022-10-26 |
| CVE-2020-22000 json | HomeAutomation 3.3.2 suffers from an authenticated OS command execution vulnerability using custom command v0.1 plugin. This ... | 8 - HIGH | 2021-04-27 | 2021-05-06 |
| CVE-2020-21998 json | In HomeAutomation 3.3.2 input passed via the 'redirect' GET parameter in 'api.php' script is not properly verified before bei... | 6.1 - MEDIUM | 2021-04-27 | 2021-05-06 |
| CVE-2020-21989 json | HomeAutomation 3.3.2 is affected by Cross Site Request Forgery (CSRF). The application interface allows users to perform cert... | 8.8 - HIGH | 2021-04-27 | 2021-05-06 |
| CVE-2020-21987 json | HomeAutomation 3.3.2 is affected by persistent Cross Site Scripting (XSS). XSS vulnerabilities occur when input passed via se... | 6.1 - MEDIUM | 2021-04-27 | 2021-05-10 |