Rainmachine Mini-8 Firmware vulnerabilities
3 known vulnerabilities affecting rainmachine/mini-8_firmware.
Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH1
Vulnerabilities
Page 1 of 1
CVE-2018-6908P2CRITICALCVSS 9.8≥ 4.0.539, ≤ 4.0.9752018-11-01
CVE-2018-6908 [CRITICAL] CWE-287 CVE-2018-6908: An authentication bypass vulnerability exists in the Green Electronics RainMachine Mini-8 (2nd Gener
An authentication bypass vulnerability exists in the Green Electronics RainMachine Mini-8 (2nd Generation) and Touch HD 12 web application allowing an unauthenticated attacker to perform authenticated actions on the device via a 127.0.0.1:port value in the HTTP 'Host' header, as demonstrated by retrieving credentials.
nvd
CVE-2018-6012P3CRITICALCVSS 9.8≥ 4.0.539, ≤ 4.0.9752018-11-01
CVE-2018-6012 [CRITICAL] CWE-94 CVE-2018-6012: The 'Weather Service' feature of the Green Electronics RainMachine Mini-8 (2nd generation) allows an
The 'Weather Service' feature of the Green Electronics RainMachine Mini-8 (2nd generation) allows an attacker to inject arbitrary Python code via the 'Add new weather data source' upload function.
nvd
CVE-2018-6011P3HIGHCVSS 8.1≥ 4.0.539, ≤ 4.0.9752018-11-01
CVE-2018-6011 [HIGH] CWE-287 CVE-2018-6011: The time-based one-time-password (TOTP) function in the application logic of the Green Electronics R
The time-based one-time-password (TOTP) function in the application logic of the Green Electronics RainMachine Mini-8 (2nd generation) uses the administrator's password hash to generate a 6-digit temporary passcode that can be used for remote and local access, aka a "Use of Password Hash Instead of Password for Authentication" issue. This is exploitable
nvd