Description
HomeAutomation 3.3.2 suffers from an authenticated OS command execution vulnerability using custom command v0.1 plugin. This can be exploited with a CSRF vulnerability to execute arbitrary shell commands as the web user via the 'set_command_on' and 'set_command_off' POST parameters in '/system/systemplugins/customcommand/customcommand.plugin.php' by using an unsanitized PHP exec() function.
Exploits (1)
Scores
CVSS v3
8.0
EPSS
0.0117
EPSS Percentile
78.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Details
CWE
CWE-78
CWE-352
Status
published
Products (1)
homeautomation_project/homeautomation
3.3.2
Published
Apr 27, 2021
Tracked Since
Feb 18, 2026