In Fibaro Home Center 2 and Lite devices with firmware version 4.540 and older an authenticated user can run commands as root user using a command injection vulnerability.
2021-04-19T14:15:11.787
2024-11-21T05:47:20.827
Modified
CVSSv3.1: 9.8 (CRITICAL)
AV:N/AC:L/Au:S/C:C/I:C/A:C
8.0
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | fibaro | home_center_2_firmware | ≤ 4.540 | Yes |
Hardware | fibaro | home_center_2 | - | No |
Operating System | fibaro | home_center_lite_firmware | ≤ 4.540 | Yes |
Hardware | fibaro | home_center_lite | - | No |