CVE-2018-6012

The 'Weather Service' feature of the Green Electronics RainMachine Mini-8 (2nd generation) allows an attacker to inject arbitrary Python code via the 'Add new weather data source' upload function.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:rainmachine:mini-8_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:rainmachine:mini-8:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2018-11-01 17:29

Updated : 2024-02-04 20:03


NVD link : CVE-2018-6012

Mitre link : CVE-2018-6012

CVE.ORG link : CVE-2018-6012


JSON object : View

Products Affected

rainmachine

  • mini-8_firmware
  • mini-8
CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')