CVE-2025-1184
CVSS 3.1 Score 6.3 of 10 (medium)
Details
Published Feb 12, 2025
Updated: Feb 18, 2025
CWE ID 89
CWE ID 74
Summary
CVE-2025-1184 is a critical vulnerability affecting PiHome 1.77. The issue lies within an unknown functionality of the /ajax.php?Ajax=GetModal_MQTTEdit file, where manipulation of the argument id allows for sql injection. This vulnerability is remotely exploitable, meaning an attacker can take advantage of it without requiring access to the system. The exploit for this weakness has been made public, increasing the risk of potential attacks.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Products
- Pihome