CVE-2020-22001
27.04.2021, 18:15
HomeAutomation 3.3.2 suffers from an authentication bypass vulnerability when spoofing client IP address using the X-Forwarded-For header with the local (loopback) IP address value allowing remote control of the smart home solution.Enginsight
Vendor | Product | Version |
---|---|---|
homeautomation_project | homeautomation | 3.3.2 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References