Unrated severityNVD Advisory· Published Feb 12, 2025· Updated Feb 12, 2025
pihome-shc PiHome Role-Based Access Control user_accounts.php authorization
CVE-2025-1214
Description
A vulnerability classified as critical has been found in pihome-shc PiHome 2.0. This affects an unknown part of the file /user_accounts.php?uid of the component Role-Based Access Control. The manipulation leads to missing authorization. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Affected products
1- Range: 2.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- github.com/janssensjelle/published-pocs/blob/main/pihomehvac-improper-access-control.mdmitreexploit
- vuldb.commitrethird-party-advisory
- vuldb.commitresignaturepermissions-required
- vuldb.commitrevdb-entry
News mentions
0No linked articles in our index yet.