← Back

CVE-2020-24395

nvd nist
Published: May 20, 2021Modified: Jun 17, 2026

JSON object

Loading...
6.8
Vector
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 0.9 / Impact: 5.9
Source: NVD

Description

The USB firmware update script of homee Brain Cube v2 (2.28.2 and 2.28.4) devices allows an attacker with physical access to install compromised firmware. This occurs because of insufficient validation of the firmware image file and can lead to code execution on the device.

Affected (2)

1 product
Brain Cube Core
Configuration A
2 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Hom.ee
Version 2.28.2
Version 2.28.4
Running on/withPlatform Versions
Hom.ee
Brain Cube
All versions

References (4)

Source: cve@mitre.org
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.