CVE-2019-16258

Severity CVSS v4.0:
Pending analysis
Type:
CWE-306 Missing Authentication for Critical Function
Publication date:
20/03/2020
Last modified:
03/06/2021

Description

The bootloader of the homee Brain Cube V2 through 2.23.0 allows attackers with physical access to gain root access by manipulating the U-Boot environment via the CLI after connecting to the internal UART interface.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:hom.ee:brain_cube_core:*:*:*:*:*:*:*:* 2.0.0 (including) 2.23.0 (including)
cpe:2.3:h:hom.ee:brain_cube:*:*:*:*:*:*:*:*