PoC Index

CVE-2018-15723

CRITICAL 9.8EPSS 3.7%

The Logitech Harmony Hub before version 4.15.206 is vulnerable to application level command injection via crafted HTTP request. An unauthenticated remote attacker can leverage this vulnerability to execute application defined commands (e.g. harmony.system?systeminfo).

CVSS v3.0
9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0
7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS
3.70% chance of exploitation in the next 30 days, 89th percentile
Published
2018-12-20
Updated
2024-09-17

Proof-of-concept exploits (1)

References

Related