← Back

Brain Cube Core

brain_cube_core

Vendor: Hom.ee • 3 CVEs

CVEs (3)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Hom.ee
1Brain Cube Core
Jun 17, 2026
May 20, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
homee Brain Cube v2 (2.28.2 and 2.28.4) devices have sensitive SSH keys within downloadable and unencrypted firmware images. This allows remote attackers to use the support server as a SOCKS proxy.
1Hom.ee
1Brain Cube Core
Jun 17, 2026
May 20, 2021
N/A· v4
6.8 MEDIUM· v3
7.2 HIGH· v2
The USB firmware update script of homee Brain Cube v2 (2.28.2 and 2.28.4) devices allows an attacker with physical access to install compromised firmware. This occurs because of insufficient validation of the firmware im...Show more
The USB firmware update script of homee Brain Cube v2 (2.28.2 and 2.28.4) devices allows an attacker with physical access to install compromised firmware. This occurs because of insufficient validation of the firmware image file and can lead to code execution on the device.Show less
1Hom.ee
1Brain Cube Core
Jun 17, 2026
Mar 20, 2020
N/A· v4
6.8 MEDIUM· v3
7.2 HIGH· v2
The bootloader of the homee Brain Cube V2 through 2.23.0 allows attackers with physical access to gain root access by manipulating the U-Boot environment via the CLI after connecting to the internal UART interface.