VYPR

RainMachine Mini-8 (2nd Generation)

by Green Electronics

CVEs (6)

  • CVE-2018-6908CriNov 1, 2018
    risk 0.64cvss 9.8epss 0.02

    An authentication bypass vulnerability exists in the Green Electronics RainMachine Mini-8 (2nd Generation) and Touch HD 12 web application allowing an unauthenticated attacker to perform authenticated actions on the device via a 127.0.0.1:port value in the HTTP 'Host' header, as…

  • CVE-2018-6012CriNov 1, 2018
    risk 0.64cvss 9.8epss 0.01

    The 'Weather Service' feature of the Green Electronics RainMachine Mini-8 (2nd generation) allows an attacker to inject arbitrary Python code via the 'Add new weather data source' upload function.

  • CVE-2018-6907HigNov 1, 2018
    risk 0.57cvss 8.8epss 0.00

    A Cross Site Request Forgery (CSRF) vulnerability in the Green Electronics RainMachine Mini-8 (2nd Generation) and Touch HD 12 web application allows an attacker to control the RainMachine device via the REST API.

  • CVE-2018-6011HigNov 1, 2018
    risk 0.53cvss 8.1epss 0.01

    The time-based one-time-password (TOTP) function in the application logic of the Green Electronics RainMachine Mini-8 (2nd generation) uses the administrator's password hash to generate a 6-digit temporary passcode that can be used for remote and local access, aka a "Use of…

  • CVE-2018-6909MedNov 1, 2018
    risk 0.42cvss 6.5epss 0.01

    A missing X-Frame-Options header in the Green Electronics RainMachine Mini-8 (2nd Generation) and Touch HD 12 web application could be used by a remote attacker for clickjacking, as demonstrated by triggering an API page request.

  • CVE-2018-6906MedNov 1, 2018
    risk 0.40cvss 6.1epss 0.01

    A persistent Cross Site Scripting (XSS) vulnerability in the Green Electronics RainMachine Mini-8 (2nd Generation) and Touch HD 12 web application allows an attacker to inject arbitrary JavaScript via the REST API.