CVE-2017-13664: Ismartalarm Cubeone Firmware

Critical severity, CVSS 9.8. EPSS: 1.5% chance of exploitation in the next 30 days.

Password file exposure in firmware in iSmartAlarm CubeOne version 2.2.4.8 and earlier allows attackers to execute arbitrary commands with administrative privileges by retrieving credentials from this file.

Affected products

  • Ismartalarm Cubeone Firmware: up to and including 2.2.4.8

Published 2017-12-01. Last modified 2026-06-17.