CVE-2011-4837: Homeseer HS2

Medium severity, CVSS 6.8. EPSS: 2% chance of exploitation in the next 30 days.

Cross-site request forgery (CSRF) vulnerability in /ctrl in the web interface in HomeSeer HS2 2.5.0.20 allows remote attackers to hijack the authentication of admins for requests that execute arbitrary programs.

Affected products

  • Homeseer Homeseer HS2: version 2.5.0.20 only

Published 2011-12-15. Last modified 2026-06-16.