Exploitation Summary
EIP tracks 1 public exploit for CVE-2013-4865. PoCs published by Trustwave's SpiderLabs.
AI-analyzed exploit summary The exploit demonstrates multiple vulnerabilities in MiCasaVerde VeraLite, including path traversal, insufficient authorization checks, and CSRF. It provides proof-of-concept code for arbitrary file disclosure, privilege escalation via firmware updates, and remote code execution through Lua code injection.
Description
Cross-site request forgery (CSRF) vulnerability in upgrade_step2.sh in MiCasaVerde VeraLite with firmware 1.5.408 allows remote attackers to hijack the authentication of users for requests that install arbitrary firmware via the squashfs parameter.
Exploits (1)
The exploit demonstrates multiple vulnerabilities in MiCasaVerde VeraLite, including path traversal, insufficient authorization checks, and CSRF. It provides proof-of-concept code for arbitrary file disclosure, privilege escalation via firmware updates, and remote code execution through Lua code injection.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N