ZDI-26-562: (Pwn2Own) Home Assistant Green mDNS Server-Side Request Forgery Vulnerability
ZDI-26-562 details an unauthenticated, network-adjacent SSRF in the Home Assistant Green mDNS server, rated CVSS 5.4 and originally demonstrated at Pwn2Own.
A server-side request forgery in Home Assistant Green's mDNS service lets network-adjacent attackers initiate arbitrary server-side requests without authentication. The Zero Day Initiative assigned the flaw a CVSS 5.4 rating under advisory ZDI-26-562. The finding originated from Pwn2Own, and no exploitation in the wild is reported.
- Unauthenticated network-adjacent attackers can trigger arbitrary server-side requests
- Tracked as ZDI-26-562 with a CVSS 5.4 rating
- Disclosed as a Pwn2Own finding; no in-the-wild exploitation reported
- Affects the Home Assistant Green hub
This vulnerability allows network-adjacent attackers to initiate arbitrary server-side requests on affected installations of Home Assistant Green. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 5.4.
This source does not provide full text. Read it at zerodayinitiative.com.