SQL Injection Vulnerability in Pi.Alert Wi-Fi/LAN Intruder Detector
CVE-2026-44886

8.7HIGH

Key Information:

Vendor

Leiweibau

Status
Vendor
CVE Published:
27 May 2026

What is CVE-2026-44886?

The Pi.Alert web service, responsible for detecting unauthorized access via Wi-Fi and LAN, contains a SQL injection vulnerability that can be exploited by unauthenticated users. This flaw exists in the devices.php endpoint, where an attacker can manipulate the action parameter to gain unauthorized access to sensitive database information. The vulnerability is present from June 29, 2024, until it is resolved on May 7, 2026. Users are advised to ensure their systems are updated to prevent exploitation as detailed in the security advisory.

Affected Version(s)

Pi.Alert >= 2024-06-29, < 2026-05-07

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.