CVE-2023-36622 Information
Jul 06, 2023
cve
Description
The websocket configuration endpoint of the Loxone Miniserver Go Gen.2 before 14.1.5.9 allows remote authenticated administrators to inject arbitrary OS commands via the timezone parameter.
Reference
https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2023-012.txt https://www.syss.de/pentest-blog/root-zugang-zu-smarthome-server-loxone-miniserver-go-gen-2-syss-2023-004/-012/-013
Share on: