Smartwares HOME easy 1.0.9 contains an authentication bypass vulnerability that allows unauthenticated attackers to access administrative web pages by disabling JavaScript. Attackers can navigate to multiple administrative endpoints and to bypass client-side validation and access sensitive system information.
Metrics
Affected Vendors & Products
References
History
Wed, 24 Dec 2025 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Smartwares HOME easy 1.0.9 contains an authentication bypass vulnerability that allows unauthenticated attackers to access administrative web pages by disabling JavaScript. Attackers can navigate to multiple administrative endpoints and to bypass client-side validation and access sensitive system information. | |
| Title | Smartwares HOME easy 1.0.9 Client-Side Authentication Bypass via Web Pages | |
| Weaknesses | CWE-639 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2025-12-24T20:23:58.323Z
Reserved: 2025-12-24T14:27:12.475Z
Link: CVE-2019-25235
No data.
Status : Received
Published: 2025-12-24T20:15:51.070
Modified: 2025-12-24T20:15:51.070
Link: CVE-2019-25235
No data.
OpenCVE Enrichment
No data.