MiCasaVerde VeraLite UPnP RCE
Critical Nessus Plugin ID 93911
SynopsisThe remote device is affected by a remote code execution vulnerability.
DescriptionThe remote MiCasaVerde VeraLite Smart Home Controller is affected by a remote code execution vulnerability. An unauthenticated, remote attacker can exploit this, via the UPnP RunLua action, to execute arbitrary shell commands as root.
Note that MiCasaVerde VeraLite is reportedly affected by additional vulnerabilities; however, Nessus has not tested for these.
SolutionThe vendor has stated that they will not patch the vulnerability.