CVE-2019-25235

CRITICAL

Smartwares HOME easy <1.0.9 - Auth Bypass

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2019-25235. PoCs published by LiquidWorm.

AI-analyzed exploit summary This is a writeup describing a client-side authentication bypass vulnerability in Smartwares HOME easy <=1.0.9. The vulnerability allows unauthorized access to administrative pages and SQLite3 database files by disabling JavaScript or navigating directly to specific URLs.

Description

Smartwares HOME easy 1.0.9 contains an authentication bypass vulnerability that allows unauthenticated attackers to access administrative web pages by disabling JavaScript. Attackers can navigate to multiple administrative endpoints and to bypass client-side validation and access sensitive system information.

Exploits (1)

exploitdb WRITEUP
by LiquidWorm · textwebappshardware
https://www.exploit-db.com/exploits/47595

This is a writeup describing a client-side authentication bypass vulnerability in Smartwares HOME easy <=1.0.9. The vulnerability allows unauthorized access to administrative pages and SQLite3 database files by disabling JavaScript or navigating directly to specific URLs.

Classification
Writeup 90%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: Smartwares HOME easy <=1.0.9
No auth needed
Prerequisites: Network access to the target device · Web browser with JavaScript disabled or ability to navigate to specific URLs
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Various Sources product
https://www.smartwares.eu
Third Party Advisory third-party-advisory
https://www.zeroscience.mk/en/vulnerabilities/ZSL-2019-5540.php
Exploit, Third Party Advisory exploit
https://www.exploit-db.com/exploits/47595

Scores

CVSS v3 9.8
EPSS 0.0043
EPSS Percentile 34.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-639
Status published
Products (1)
Smartwares/Smartwares HOME easy 1.0.9
Published Dec 24, 2025
Tracked Since Feb 18, 2026