CVE-2018-6012

CRITICAL

RainMachine Mini-8 - Code Injection

Title source: llm
STIX 2.1

Description

The 'Weather Service' feature of the Green Electronics RainMachine Mini-8 (2nd generation) allows an attacker to inject arbitrary Python code via the 'Add new weather data source' upload function.

References (1)

Core 1

Scores

CVSS v3 9.8
EPSS 0.0134
EPSS Percentile 67.8%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-94
Status published
Products (1)
rainmachine/mini-8_firmware 4.0.539 - 4.0.975
Published Nov 01, 2018
Tracked Since Feb 18, 2026