CVEs Blog | G5 Cyber Security

CVE-2020-22001 – HomeAutomation 3.3.2 suffers from an authentication bypass vulnerability

HomeAutomation 3.3.2 suffers from an authentication bypass vulnerability when spoofing client IP address using the X-Forwarded-For header with the local (loopback) IP address value allowing remote control of the smart home solution.

 

Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-22001

Reference (s):

Exit mobile version