CVE-2019-25235

CRITICAL

Smartwares HOME easy <1.0.9 - Auth Bypass

Title source: llm

Description

Smartwares HOME easy 1.0.9 contains an authentication bypass vulnerability that allows unauthenticated attackers to access administrative web pages by disabling JavaScript. Attackers can navigate to multiple administrative endpoints and to bypass client-side validation and access sensitive system information.

Exploits (1)

exploitdb WRITEUP
by LiquidWorm · textwebappshardware
https://www.exploit-db.com/exploits/47595

Scores

CVSS v3 9.8
EPSS 0.0037
EPSS Percentile 58.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-639
Status published
Products (1)
Smartwares/Smartwares HOME easy 1.0.9
Published Dec 24, 2025
Tracked Since Feb 18, 2026