Gallery

Contacts

405 W. Greenlawn Ave Lansing, Michigan 48910

contact@techjacksolutions.com

+1-616-320-4064

A critical unauthenticated remote code execution vulnerability in MajorDoMo, an open-source home automation platform, allows any attacker to run arbitrary commands on affected systems without credentials. The vulnerability stems from a missing exit statement after a redirect call and direct use of user-supplied input in PHP’s eval() function. CISA has confirmed active exploitation (see CISA Known Exploited Vulnerabilities Catalog); organizations running MajorDoMo with the admin panel PHP console enabled should treat this as an immediate containment priority.

Author

Tech Jacks Solutions