PT-2026-28606 · Unknown · Home Assistant
CVE-2026-34205
·
Publicado
2026-03-27
·
Atualizado
2026-06-19
CVSS v3.1
9.6
Crítica
| Vetor | AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Home Assistant versions prior to 2026.03.02
Description
Home Assistant is open source home automation software focused on local control and privacy. Home Assistant apps, when configured with host network mode, expose unauthenticated endpoints bound to the internal Docker bridge interface to the local network. This configuration does not restrict access to the app as intended, allowing any device on the same network to reach these endpoints without authentication.
Recommendations
Update to Home Assistant Supervisor version 2026.03.02 or later.
Correção
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Home Assistant