Smartwares HOME easy 1.0.9 contains an authentication bypass vulnerability that allows unauthenticated attackers to access administrative web pages by disabling JavaScript. Attackers can navigate to multiple administrative endpoints and to bypass client-side validation and access sensitive system information.
References
Configurations
No configuration.
History
No history.
Information
Published : 2025-12-24 20:15
Updated : 2025-12-29 15:58
NVD link : CVE-2019-25235
Mitre link : CVE-2019-25235
CVE.ORG link : CVE-2019-25235
JSON object : View
Products Affected
No product.
CWE
CWE-639
Authorization Bypass Through User-Controlled Key
