The Logitech Harmony Hub before version 4.15.206 is vulnerable to OS command injection via the time update request. A remote server or man in the middle can inject OS commands with a properly formatted response.
2018-12-20T21:29:00.727
2024-11-21T03:51:20.583
Modified
CVSSv3.0: 8.1 (HIGH)
AV:N/AC:M/Au:N/C:C/I:C/A:C
8.6
10.0
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Operating System | logitech | harmony_hub_firmware | < 4.15.206 | Yes |
| Hardware | logitech | harmony_hub | - | No |