CVE-2020-21989

HIGH

HomeAutomation 3.3.2 - Cross-Site Request Forgery

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2020-21989. PoCs published by LiquidWorm.

AI-analyzed exploit summary This is a functional CSRF exploit for HomeAutomation v3.3.2 that adds an admin user via a crafted HTML form. The exploit leverages lack of CSRF tokens to perform unauthorized administrative actions.

Description

HomeAutomation 3.3.2 is affected by Cross Site Request Forgery (CSRF). The application interface allows users to perform certain actions via HTTP requests without performing any validity checks to verify the requests. This can be exploited to perform certain actions with administrative privileges if a logged-in user visits a malicious web site.

Exploits (1)

exploitdb WORKING POC VERIFIED
by LiquidWorm · textwebappsphp
https://www.exploit-db.com/exploits/47808

This is a functional CSRF exploit for HomeAutomation v3.3.2 that adds an admin user via a crafted HTML form. The exploit leverages lack of CSRF tokens to perform unauthorized administrative actions.

Classification
Working Poc 100%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: HomeAutomation v3.3.2
No auth needed
Prerequisites: Victim must be logged into the target application · Attacker must lure victim to a malicious page
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (2)

Core 2
Core References
Exploit, Third Party Advisory x_refsource_misc
https://www.zeroscience.mk/en/vulnerabilities/ZSL-2019-5558.php
Exploit, Third Party Advisory, VDB Entry exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/47808

Scores

CVSS v3 8.8
EPSS 0.0075
EPSS Percentile 50.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-352
Status published
Products (1)
homeautomation_project/homeautomation 3.3.2
Published Apr 27, 2021
Tracked Since Feb 18, 2026