CVE-2018-6012

The 'Weather Service' feature of the Green Electronics RainMachine Mini-8 (2nd generation) allows an attacker to inject arbitrary Python code via the 'Add new weather data source' upload function.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:rainmachine:mini-8_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:rainmachine:mini-8:-:*:*:*:*:*:*:*

Information

Published : 2018-11-01 10:29

Updated : 2019-02-22 09:07


NVD link : CVE-2018-6012

Mitre link : CVE-2018-6012


JSON object : View

CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')

Advertisement

dedicated server usa

Products Affected

rainmachine

  • mini-8_firmware
  • mini-8