ZDI-CAN-28340: ZDI-26-560: (Pwn2Own) Home Assistant Green go2rtc Command Injection Remote Code Execution Vulnerability
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Home Assistant Green. An attacker must first obtain the ability to access the device's localhost interface. The ZDI has assigned a CVSS rating of 7.5.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-28340?
The severity of ZDI-CAN-28340 is assessed with a CVSS rating of 7.5, indicating high risk.
How do I fix ZDI-CAN-28340?
To fix ZDI-CAN-28340, users should apply the latest security patches provided by Home Assistant.
What does ZDI-CAN-28340 exploit?
ZDI-CAN-28340 exploits a command injection vulnerability allowing remote code execution on Home Assistant Green installations.
Who is affected by ZDI-CAN-28340?
All users of Home Assistant Green who have not secured their localhost interface may be affected by ZDI-CAN-28340.
Can ZDI-CAN-28340 be exploited remotely?
Yes, ZDI-CAN-28340 can be exploited by attackers who can access the localhost interface of the affected device.