var-202404-0001

HIGH CVSS 8.1 variot
Description

Multiple smart home hub devices are vulnerable to command injection via the cloud API.

Timeline
Published
2024-04-18 10:00 UTC
Last Modified
2024-05-01
CVSS Details

CVSS details not available.

Affected Products

No product information available.

CVSS metrics
Version Base Severity Vector Exploitability Impact Source
3.1 8.1 HIGH
References

No references available.

Linked Vulnerabilities

No linked vulnerabilities found.

{
  "cvss": 8.1,
  "datePublished": "2024-04-18T10:00:00Z",
  "dateUpdated": "2024-05-01T18:00:00Z",
  "description": "Multiple smart home hub devices are vulnerable to command injection via the cloud API.",
  "id": "VAR-202404-0001",
  "metrics": {
    "cvssMetricV31": [
      {
        "cvssData": {
          "baseScore": 8.1,
          "baseSeverity": "HIGH",
          "version": "3.1"
        }
      }
    ]
  },
  "severity": "HIGH",
  "source": "variot",
  "title": "VARIoT: Smart Home Hub Command Injection"
}
View JSON API Download JSON