ZDI-26-560: (Pwn2Own) Home Assistant Green go2rtc Command Injection Remote Code Execution Vulnerability
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Home Assistant Green. An attacker must first obtain the ability to access the device's localhost interface. The ZDI has assigned a CVSS rating of 7.5.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-26-560?
The severity of ZDI-26-560 is rated at 7.5 on the CVSS scale.
How do I fix ZDI-26-560?
To fix ZDI-26-560, ensure that your Home Assistant Green is updated to the latest version that addresses this vulnerability.
What type of attacks can be conducted using ZDI-26-560?
ZDI-26-560 allows network-adjacent attackers to execute arbitrary code on affected installations of Home Assistant Green.
Who is vulnerable to ZDI-26-560?
Users of Home Assistant Green who have exposed their device's localhost interface to the network are vulnerable to ZDI-26-560.
What should I do if I am affected by ZDI-26-560?
If affected by ZDI-26-560, it is critical to apply the provided updates to mitigate the risk of remote code execution.