CVE-2020-24396: Hom.ee Brain Cube Core
High severity, CVSS 7.5. EPSS: 1.9% chance of exploitation in the next 30 days.
homee Brain Cube v2 (2.28.2 and 2.28.4) devices have sensitive SSH keys within downloadable and unencrypted firmware images. This allows remote attackers to use the support server as a SOCKS proxy.
Affected products
- Hom.ee Brain Cube Core: version 2.28.2 only; version 2.28.4 only
Published 2021-05-20. Last modified 2026-06-17.