ZeroHour

CVE-2018-15723

PoC
CVSS 3.0
9.8 critical
EPSS
4%p89
Published
()
Modified
Description

The Logitech Harmony Hub before version 4.15.206 is vulnerable to application level command injection via crafted HTTP request. An unauthenticated remote attacker can leverage this vulnerability to execute application defined commands (e.g. harmony.system?systeminfo).

Vendors
logitech
Products
harmony hub firmware
Weakness
CWE-346
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.