ZeroHour

CVE-2023-36622

PoC
CVSS 3.1
7.2 high
EPSS
1%p70
Published
()
Modified
Description

The websocket configuration endpoint of the Loxone Miniserver Go Gen.2 before 14.1.5.9 allows remote authenticated administrators to inject arbitrary OS commands via the timezone parameter.

Vendors
loxone
Products
miniserver go gen 2 firmware
Weakness
CWE-78
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.