First published: Sun Jul 14 2019(Updated: )
LuaUPnP in Vera Edge Home Controller 1.7.4452 allows remote unauthenticated users to execute arbitrary OS commands via the code parameter to /port_3480/data_request because the "No unsafe lua allowed" code block is skipped.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Getvera VeraEdge Firmware | =1.7.4452 | |
Getvera Vera Edge Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-13598 is a vulnerability in the Vera Edge Home Controller firmware version 1.7.4452 that allows remote unauthenticated users to execute arbitrary OS commands.
CVE-2019-13598 has a severity rating of 9.8 (Critical).
Vera Edge Home Controller firmware version 1.7.4452 is affected by CVE-2019-13598.
The vulnerability can be exploited by remote unauthenticated users who send a code parameter to /port_3480/data_request.
It is recommended to update the Vera Edge Home Controller firmware to a version that is not affected by the vulnerability.