CVE-2023-36622: Loxone Miniserver Go Gen 2 Firmware
High severity, CVSS 7.2. EPSS: 1.4% chance of exploitation in the next 30 days.
The websocket configuration endpoint of the Loxone Miniserver Go Gen.2 before 14.1.5.9 allows remote authenticated administrators to inject arbitrary OS commands via the timezone parameter.
Affected products
- Loxone Miniserver Go Gen 2 Firmware: before 14.1.5.9 (fixed in 14.1.5.9)
Published 2023-07-05. Last modified 2026-06-17.