CVE-2019-25235: Smartwares Home Easy
Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.
Smartwares HOME easy 1.0.9 contains an authentication bypass vulnerability that allows unauthenticated attackers to access administrative web pages by disabling JavaScript. Attackers can navigate to multiple administrative endpoints and to bypass client-side validation and access sensitive system information.
Affected products
- Smartwares Smartwares Home Easy: version 1.0.9 only
Published 2025-12-24. Last modified 2026-06-17.