Hom.Ee's vulnerability profile centers on its Brain Cube smart-home automation platform and related core components, focusing on consumer and residential infrastructure. The durable signal reflects authentication and credential-handling weaknesses, including insufficient data-authenticity verification, inadequately protected credentials, and missing authentication controls for critical functions—issues characteristic of IoT and home-automation devices where secure-by-default design and secret management are often underprioritized.
The number and severity of CVEs published that impact products developed by Hom.Ee over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-24396HIGH homee Brain Cube v2 (2.28.2 and 2.28.4) devices have sensitive SSH keys within downloadable and unencrypted firmware images. This allows remote attackers to use the support server | May 20, 2021 | 7.5 | 25 | NO | NO |
CVE-2019-16258MEDIUM The bootloader of the homee Brain Cube V2 through 2.23.0 allows attackers with physical access to gain root access by manipulating the U-Boot environment via the CLI after connecti | Mar 20, 2020 | 6.8 | 23 | NO | NO |
CVE-2020-24395MEDIUM The USB firmware update script of homee Brain Cube v2 (2.28.2 and 2.28.4) devices allows an attacker with physical access to install compromised firmware. This occurs because of in | May 20, 2021 | 6.8 | 18 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Hom.Ee.
Media articles that mention a CVE ID that affects a product developed by Hom.Ee — matched by CVE ID, not by vendor name.