Homeautomation Project develops a home automation platform where its vulnerability footprint centers on application-layer defenses, with recurring issues spanning cross-site request forgery, authentication bypass, cross-site scripting, OS command injection, and open redirect flaws. These weakness classes reflect typical web-application input-handling and session-management risks in internet-facing automation interfaces; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Homeautomation Project over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-22001CRITICAL HomeAutomation 3.3.2 suffers from an authentication bypass vulnerability when spoofing client IP address using the X-Forwarded-For header with the local (loopback) IP address value | Apr 27, 2021 | 9.8 | 30 | NO | NO |
CVE-2020-21998MEDIUM In HomeAutomation 3.3.2 input passed via the 'redirect' GET parameter in 'api.php' script is not properly verified before being used to redirect users. This can be exploited to red | Apr 27, 2021 | 6.1 | 30 | NO | YES |
CVE-2020-22000HIGH HomeAutomation 3.3.2 suffers from an authenticated OS command execution vulnerability using custom command v0.1 plugin. This can be exploited with a CSRF vulnerability to execute a | Apr 27, 2021 | 8.0 | 25 | NO | NO |
CVE-2020-21989HIGH HomeAutomation 3.3.2 is affected by Cross Site Request Forgery (CSRF). The application interface allows users to perform certain actions via HTTP requests without performing any va | Apr 27, 2021 | 8.8 | 25 | NO | NO |
CVE-2020-21987MEDIUM HomeAutomation 3.3.2 is affected by persistent Cross Site Scripting (XSS). XSS vulnerabilities occur when input passed via several parameters to several scripts is not properly san | Apr 27, 2021 | 6.1 | 20 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Homeautomation Project.
Media articles that mention a CVE ID that affects a product developed by Homeautomation Project — matched by CVE ID, not by vendor name.