CVE-2020-24395

MEDIUM

homee Brain Cube <2.28.4 - Code Injection

Title source: llm
STIX 2.1

Description

The USB firmware update script of homee Brain Cube v2 (2.28.2 and 2.28.4) devices allows an attacker with physical access to install compromised firmware. This occurs because of insufficient validation of the firmware image file and can lead to code execution on the device.

References (2)

Core 2
Core References
Third Party Advisory x_refsource_misc
https://www.syss.de/pentest-blog/

Scores

CVSS v3 6.8
EPSS 0.0024
EPSS Percentile 14.8%
Attack Vector PHYSICAL
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-345
Status published
Products (2)
hom.ee/brain_cube_core 2.28.2
hom.ee/brain_cube_core 2.28.4
Published May 20, 2021
Tracked Since Feb 18, 2026