Description
The bootloader of the homee Brain Cube V2 through 2.23.0 allows attackers with physical access to gain root access by manipulating the U-Boot environment via the CLI after connecting to the internal UART interface.
References (2)
Core 2
Core References
Product, Vendor Advisory x_refsource_misc
https://store.hom.ee/collections/all/products/homee-brain-cube
Third Party Advisory x_refsource_misc
https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2019-026.txt
Scores
CVSS v3
6.8
EPSS
0.0030
EPSS Percentile
21.3%
Attack Vector
PHYSICAL
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-306
Status
published
Products (1)
hom.ee/brain_cube_core
2.0.0 - 2.23.0
Published
Mar 20, 2020
Tracked Since
Feb 18, 2026