ZDI-26-561: (Pwn2Own) Home Assistant Green go2rtc Command Injection Remote Code Execution Vulnerability
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Home Assistant Green. An attacker must first obtain the ability to access the device's localhost interface. The ZDI has assigned a CVSS rating of 7.5.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-26-561?
The severity of ZDI-26-561 is rated with a CVSS score of 7.5, indicating high risk.
How do I fix ZDI-26-561?
To fix ZDI-26-561, ensure that your Home Assistant Green installation is updated to the latest version containing the security patch.
What type of attacks can exploit ZDI-26-561?
ZDI-26-561 can be exploited by network-adjacent attackers for command injection and remote code execution.
Who is affected by ZDI-26-561?
ZDI-26-561 affects installations of Home Assistant Green that allow access to the localhost interface.
What should I do if I suspect exploitation of ZDI-26-561?
If you suspect exploitation of ZDI-26-561, immediately review logs for unauthorized access and apply the recommended security updates.