Record summary

CVE-2020-21998 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

In HomeAutomation 3.3.2 input passed via the 'redirect' GET parameter in 'api.php' script is not properly verified before being used to redirect users. This can be exploited to redirect a user to an arbitrary website e.g. when a user clicks a specially crafted link to the affected script hosted on a trusted domain.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryMEDIUMHomeAutomation 3.3.2 - Open RedirectCVSS 6.1

HomeAutomation 3.3.2 contains a redirect vulnerability caused by improper verification of the 'redirect' GET parameter in 'api.php', letting attackers redirect users to arbitrary websites, exploit requires user interaction with a crafted link.

Impact

Attackers can redirect users to malicious external websites through crafted links, potentially facilitating phishing attacks or malware distribution.

Remediation

Upgrade to HomeAutomation version 3.3.3 or later, or apply vendor-provided security patches.

WeaknessesCWE-601
Authors0x_Akoko
Template tagscvecve2020homeautomationpacketstormiotredirectvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:homeautomation_project:homeautomation:3.3.2:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

3