CVE-2020-24396

HIGH

homee Brain Cube <2.28.2,2.28.4 - Info Disclosure

Title source: llm
STIX 2.1

Description

homee Brain Cube v2 (2.28.2 and 2.28.4) devices have sensitive SSH keys within downloadable and unencrypted firmware images. This allows remote attackers to use the support server as a SOCKS proxy.

References (3)

Core 3
Core References
Third Party Advisory x_refsource_misc
https://www.syss.de/pentest-blog/
Third Party Advisory x_refsource_misc
https://cwe.mitre.org/data/definitions/522.html

Scores

CVSS v3 7.5
EPSS 0.0185
EPSS Percentile 76.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-522
Status published
Products (2)
hom.ee/brain_cube_core 2.28.2
hom.ee/brain_cube_core 2.28.4
Published May 20, 2021
Tracked Since Feb 18, 2026