CVE-2020-24396: Hom.ee Brain Cube Core

High severity, CVSS 7.5. EPSS: 1.9% chance of exploitation in the next 30 days.

homee Brain Cube v2 (2.28.2 and 2.28.4) devices have sensitive SSH keys within downloadable and unencrypted firmware images. This allows remote attackers to use the support server as a SOCKS proxy.

Affected products

  • Hom.ee Brain Cube Core: version 2.28.2 only; version 2.28.4 only

Published 2021-05-20. Last modified 2026-06-17.