Common vulnerabilities and Exposures (CVE)

Skip to main content

Required CVE Record Information

Description

LuaUPnP in Vera Edge Home Controller 1.7.4452 allows remote unauthenticated users to execute arbitrary OS commands via the code parameter to /port_3480/data_request because the "No unsafe lua allowed" code block is skipped.

Updated:

This container includes required additional information provided by the CVE Program for this vulnerability.