CVE-2018-6908

CRITICAL

RainMachine Mini-8 and Touch HD 12 Firmware 4.0.539-4.0.975 - Unauthenticated Authentication Bypass via Host Header

Title source: llm
STIX 2.1

Description

An authentication bypass vulnerability exists in the Green Electronics RainMachine Mini-8 (2nd Generation) and Touch HD 12 web application allowing an unauthenticated attacker to perform authenticated actions on the device via a 127.0.0.1:port value in the HTTP 'Host' header, as demonstrated by retrieving credentials.

References (1)

Core 1

Scores

CVSS v3 9.8
EPSS 0.0160
EPSS Percentile 72.7%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-287
Status published
Products (2)
rainmachine/mini-8_firmware 4.0.539 - 4.0.975
rainmachine/touch_hd_12_firmware 4.0.539 - 4.0.974
Published Nov 01, 2018
Tracked Since Feb 18, 2026