Iobroker is an open-source home-automation and IoT integration platform centered on its administrative interface, web portal, and JavaScript controller components, which mediate communications among connected smart-home devices and services. The vulnerability profile reflects the web-facing attack surface of these components, with recurring exposure to path-traversal and cross-site scripting flaws arising from input handling in browser-accessible administration and configuration interfaces. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Iobroker over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-10765CRITICAL iobroker.admin before 3.6.12 allows attacker to include file contents from outside the `/log/file1/` directory. | Nov 20, 2019 | 9.8 | 30 | NO | NO |
CVE-2019-10767HIGH An attacker can include file contents from outside the `/adapter/xxx/` directory, where `xxx` is the name of an existent adapter like "admin". It is exploited using the administrat | Nov 21, 2019 | 7.5 | 24 | NO | NO |
CVE-2019-10771MEDIUM Characters in the GET url path are not properly escaped and can be reflected in the server response. | Nov 25, 2019 | 6.1 | 20 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Iobroker.
Media articles that mention a CVE ID that affects a product developed by Iobroker — matched by CVE ID, not by vendor name.