Loxone develops home-automation and building-control appliances, centered on its Miniserver product line across multiple hardware generations, that expose a narrow but critical attack surface through authentication and authorization weaknesses. The recurring issues—improper authentication, OS command injection, hard-coded credentials, and missing authorization checks—reflect the direct network accessibility and privileged operational role of these embedded control systems. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Loxone over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-27488CRITICAL Loxone Miniserver devices with firmware before 11.1 (aka 11.1.9.3) are unable to use an authentication method that is based on the "signature of the update package." Therefore, the | Jan 13, 2021 | 9.8 | 31 | NO | NO |
CVE-2023-36624HIGH Loxone Miniserver Go Gen.2 through 14.0.3.28 allows an authenticated operating system user to escalate privileges via the Sudo configuration. This allows the elevated execution of | Jul 5, 2023 | 7.8 | 22 | NO | NO |
CVE-2023-36623HIGH The root password of the Loxone Miniserver Go Gen.2 before 14.2 is calculated using hard-coded secrets and the MAC address. This allows a local user to calculate the root password | Jul 5, 2023 | 7.8 | 22 | NO | NO |
CVE-2023-36622HIGH The websocket configuration endpoint of the Loxone Miniserver Go Gen.2 before 14.1.5.9 allows remote authenticated administrators to inject arbitrary OS commands via the timezone p | Jul 5, 2023 | 7.2 | 19 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Loxone.
Media articles that mention a CVE ID that affects a product developed by Loxone — matched by CVE ID, not by vendor name.