CVE-2020-22001
CRITICALHomeAutomation 3.3.2 - Authentication Bypass via X-Forwarded-For Header Spoofing
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2020-22001. PoCs published by LiquidWorm.
AI-analyzed exploit summary This exploit demonstrates an authentication bypass vulnerability in HomeAutomation 3.3.2 by spoofing the client IP address using the X-Forwarded-For header with a loopback IP address. The PoC includes a curl command to bypass authentication and access restricted content.
Description
HomeAutomation 3.3.2 suffers from an authentication bypass vulnerability when spoofing client IP address using the X-Forwarded-For header with the local (loopback) IP address value allowing remote control of the smart home solution.
Exploits (1)
This exploit demonstrates an authentication bypass vulnerability in HomeAutomation 3.3.2 by spoofing the client IP address using the X-Forwarded-For header with a loopback IP address. The PoC includes a curl command to bypass authentication and access restricted content.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H