Smart home: remote command execution (RCE)

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

Smart home: remote command execution (RCE) During my spare time I am playing around with smart home/domotica/internet of things hardware and software. A while ago I decided to take a look at the security of these solutions, just because I was curious and because it’s fun. Within this research only smart home controllers were investigated. The controllers are the brain within a smart home, whenever an attacker gains access to this component, he is able to control the complete smart home. I’ve reported some vulnerabilities to the developer of the open-source project Domoticz. The developer fixed issues quickly and I’ve also commited some code for the bug fixes myself: - [Httponly flag](https://github.com/domoticz/domoticz/pull/1515/files) - [(Authenticated) SQL injection and buffer overflow](https://github.com/domoticz/domoticz/pull/1569/files) - [(Authenticated) remote command execution (fixed by the Domoticz...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息