MiCasaVerde VeraLite UPnP RCE
Critical Nessus Plugin ID 93911
Synopsis
The remote device is affected by a remote code execution vulnerability.
Description
The remote MiCasaVerde VeraLite Smart Home Controller is affected by a remote code execution vulnerability. An unauthenticated, remote attacker can exploit this, via the UPnP RunLua action, to execute arbitrary shell commands as root.
Note that MiCasaVerde VeraLite is reportedly affected by additional vulnerabilities; however, Nessus has not tested for these.
Solution
The vendor has stated that they will not patch the vulnerability.