PT-2026-107591 · Homer · Homer
CVE-2026-62252
·
Published
2026-10-07
·
Updated
2026-10-07
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Homer versions prior to 11.0.283
Description
In fresh deployments using internal authentication, the bootstrap process automatically creates an
admin account with a hard-coded password sipcapture. This password is stored as a legacy SHA-256 hex hash, and the system lacks a mechanism to force a password change upon the first login. An attacker can gain full administrative access by accessing the /api/v3/auth endpoint using these default credentials. The issue is rooted in the EnsureBootstrapAdminUser() function, which inserts the default credentials if no admin user exists, and the legacySHA256HexEqual function, which allows the use of the legacy hash.Recommendations
Update to version 11.0.283.
Exploit
Fix
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Homer