Openhab develops a home-automation and IoT integration platform whose vulnerabilities concentrate in the core application and its web interface, reflecting the complexity of managing diverse device protocols and user access at the edge. The exposure is characterized by a strong tendency toward critical-severity outcomes, with recurring weaknesses in path traversal, access control, XML entity handling, and authorization logic that are endemic to web-facing integration platforms handling untrusted input and user permissions. Current exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Openhab over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-42469CRITICAL openHAB, a provider of open-source home automation software, has add-ons including the visualization add-on CometVisu. Prior to version 4.2.1, CometVisu's file system endpoints don | Aug 12, 2024 | 9.8 | 31 | NO | NO |
CVE-2024-42467CRITICAL openHAB, a provider of open-source home automation software, has add-ons including the visualization add-on CometVisu. Prior to version 4.2.1, the proxy endpoint of openHAB's Comet | Aug 12, 2024 | 10.0 | 29 | NO | NO |
CVE-2024-42470CRITICAL openHAB, a provider of open-source home automation software, has add-ons including the visualization add-on CometVisu. Several endpoints in versions prior to 4.2.1 of the CometVisu | Aug 12, 2024 | 9.1 | 25 | NO | NO |
CVE-2024-42468HIGH openHAB, a provider of open-source home automation software, has add-ons including the visualization add-on CometVisu. CometVisuServlet in versions prior to 4.2.1 is susceptible to | Aug 12, 2024 | 7.5 | 22 | NO | NO |
CVE-2020-5242HIGH openHAB before 2.5.2 allow a remote attacker to use REST calls to install the EXEC binding or EXEC transformation service and execute arbitrary commands on the system with the priv | Feb 20, 2020 | 8.8 | 22 | NO | NO |
CVE-2021-21266MEDIUM openHAB is a vendor and technology agnostic open source automation software for your home. In openHAB before versions 2.5.12 and 3.0.1 the XML external entity (XXE) attack allows a | Feb 1, 2021 | 5.0 | 18 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Openhab.
Media articles that mention a CVE ID that affects a product developed by Openhab — matched by CVE ID, not by vendor name.