CVE-2013-4864: Micasaverde Veralite Firmware

Critical severity, CVSS 9.8. EPSS: 6.3% chance of exploitation in the next 30 days.

MiCasaVerde VeraLite with firmware 1.5.408 allows remote attackers to send HTTP requests to intranet servers via the url parameter to cgi-bin/cmh/proxy.sh, related to a Server-Side Request Forgery (SSRF) issue.

Affected products

Published 2020-01-28. Last modified 2026-06-16.