Authentication Bypass Vulnerability in Logitech Harmony Hub
CVE-2018-15721
9.8CRITICAL
What is CVE-2018-15721?
The XMPP server in Logitech Harmony Hub versions prior to 4.15.206 is susceptible to an authentication bypass. This vulnerability allows remote attackers to send specially crafted XMPP requests, potentially granting them unauthorized access to the local API. Exploiting this flaw could enable malicious users to manipulate connected devices and access sensitive information.
Affected Version(s)
Logitech Harmony Hub Firmware before 4.15.206
