ZeroHour
ZDI Published Advisoriespublished ()ingested

ZDI-26-562: (Pwn2Own) Home Assistant Green mDNS Server-Side Request Forgery Vulnerability

mediumVulnerabilityimportance 25
AI summary · glm-5.3-flash

ZDI-26-562 details an unauthenticated, network-adjacent SSRF in the Home Assistant Green mDNS server, rated CVSS 5.4 and originally demonstrated at Pwn2Own.

A server-side request forgery in Home Assistant Green's mDNS service lets network-adjacent attackers initiate arbitrary server-side requests without authentication. The Zero Day Initiative assigned the flaw a CVSS 5.4 rating under advisory ZDI-26-562. The finding originated from Pwn2Own, and no exploitation in the wild is reported.

  • Unauthenticated network-adjacent attackers can trigger arbitrary server-side requests
  • Tracked as ZDI-26-562 with a CVSS 5.4 rating
  • Disclosed as a Pwn2Own finding; no in-the-wild exploitation reported
  • Affects the Home Assistant Green hub
Full article

This vulnerability allows network-adjacent attackers to initiate arbitrary server-side requests on affected installations of Home Assistant Green. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 5.4.

This source does not provide full text. Read it at zerodayinitiative.com.