CVE-2024-23978: Kddi Home Spot Cube 2 Firmware

Critical severity, CVSS 9.8. EPSS: 0.7% chance of exploitation in the next 30 days.

Heap-based buffer overflow vulnerability exists in HOME SPOT CUBE2 V102 and earlier. By processing invalid values, arbitrary code may be executed. Note that the affected products are no longer supported.

Affected products

  • Kddi Home Spot Cube 2 Firmware: version v102 only

Published 2024-02-02. Last modified 2026-06-17.