LuaUPnP in Vera Edge Home Controller 1.7.4452 allows remote unauthenticated users to execute arbitrary OS commands via the code parameter to /port_3480/data_request because the "No unsafe lua allowed" code block is skipped.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
getvera vera_edge_firmware 1.7.4452 |