vendor:
Heat Pump
by:
Jelmer de Hen
9,8
CVSS
HIGH
Remote Code Execution
78
CWE
Product Name: Heat Pump
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2009
NIBE Heat Pump RCE Exploit
This exploit allows an attacker to execute arbitrary commands on a vulnerable NIBE heat pump. The web interface of the heat pump is running with root rights, allowing the attacker to execute any command with root privileges. The exploit is based on the fact that the web interface does not properly validate user input, allowing an attacker to inject malicious commands into the web interface.
Mitigation:
Ensure that user input is properly validated and that the web interface is not running with root privileges.