Pihome's vulnerability footprint centers on its MaxAir product, a web-facing application where the durable signal is dominated by input-handling and authorization weaknesses including code injection, cross-site scripting, SQL injection, and improper authorization controls. These patterns reflect typical risks in web applications where user input flows directly into code execution, page rendering, and database queries without adequate sanitization or access validation. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Pihome over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-1185HIGH A vulnerability was found in pihome-shc PiHome 2.0. It has been classified as critical. This affects an unknown part of the file /ajax.php?Ajax=GetModal_Sensor_Graph. The manipulat | Feb 12, 2025 | 8.8 | 24 | NO | NO |
CVE-2025-1214HIGH A vulnerability classified as critical has been found in pihome-shc PiHome 2.0. This affects an unknown part of the file /user_accounts.php?uid of the component Role-Based Access C | Feb 12, 2025 | 8.8 | 23 | NO | NO |
CVE-2025-1184HIGH A vulnerability was found in pihome-shc PiHome 1.77 and classified as critical. Affected by this issue is some unknown functionality of the file /ajax.php?Ajax=GetModal_MQTTEdit. T | Feb 12, 2025 | 8.8 | 23 | NO | NO |
CVE-2025-1742MEDIUM A vulnerability, which was classified as problematic, has been found in pihome-shc PiHome 2.0. Affected by this issue is some unknown functionality of the file /home.php. The manip | Feb 27, 2025 | 6.1 | 18 | NO | NO |
CVE-2025-1213MEDIUM A vulnerability was found in pihome-shc PiHome 1.77. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /index.php. The manipulation | Feb 12, 2025 | 5.4 | 17 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Pihome.
Media articles that mention a CVE ID that affects a product developed by Pihome — matched by CVE ID, not by vendor name.