Micasaverde develops home-automation control systems centered on its VeraLite platform, a modest but established product line in the residential IoT space. The durable vulnerability signal concentrates on access-control and server-side handling weaknesses—chiefly cross-site request forgery, improper authentication and authorization, path traversal, and server-side request forgery—that recur across its firmware and control interfaces and reflect the inherent challenges of web-facing automation appliances. Current exploitation activity and severity figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Micasaverde over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2013-4864CRITICAL MiCasaVerde VeraLite with firmware 1.5.408 allows remote attackers to send HTTP requests to intranet servers via the url parameter to cgi-bin/cmh/proxy.sh, related to a Server-Side | Jan 28, 2020 | 9.8 | 37 | NO | YES |
CVE-2013-4863HIGH The HomeAutomationGateway service in MiCasaVerde VeraLite with firmware 1.5.408 allows (1) remote attackers to execute arbitrary Lua code via a RunLua action in a request to upnp/c | Jan 28, 2020 | 8.8 | 37 | NO | YES |
CVE-2013-4862HIGH MiCasaVerde VeraLite with firmware 1.5.408 does not properly restrict access, which allows remote authenticated users to (1) update the firmware via the squashfs parameter to upgra | Jan 28, 2020 | 8.1 | 31 | NO | YES |
CVE-2013-4865MEDIUM Cross-site request forgery (CSRF) vulnerability in upgrade_step2.sh in MiCasaVerde VeraLite with firmware 1.5.408 allows remote attackers to hijack the authentication of users for | Jan 28, 2020 | 6.5 | 30 | NO | YES |
CVE-2013-4861MEDIUM Directory traversal vulnerability in cgi-bin/cmh/get_file.sh in MiCasaVerde VeraLite with firmware 1.5.408 allows remote authenticated users to read arbirary files via a .. (dot do | Jan 28, 2020 | 6.5 | 28 | NO | YES |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Micasaverde.
Media articles that mention a CVE ID that affects a product developed by Micasaverde — matched by CVE ID, not by vendor name.