← Zurück zur CVE-Suche

CVE-2026-44888

Pi.Alert

Beschreibung

Pi.Alert is a WIFI / LAN intruder detector with web service monitoring. Prior to 2026-05-07, Pi.Alert-s SaveConfigFile() endpoint writes user-supplied numeric config values (e.g., SMTP_PORT) directly into pialert.conf without validation. Since pialert.conf is loaded via Python-s exec() every 3–5 minutes by the background cron process, an attacker can inject arbitrary Python code and achieve unauthenticated OS-level RCE. On default installations (PIALERT_WEB_PROTECTION = False), no credentials are required. This vulnerability is fixed in 2026-05-07.

CVSS 9.8EPSS 0.314%Risiko 1.01
Quelle öffnen
Veröffentlicht
2026-05-27 20:16:38
Betroffene Versionen
unknown
Typ
Core software
Vektor
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H