<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T23:50:30.817689+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-54317</id>
    <title>CVE-2026-54317 — Home Assistant: Konnected alarm-panel switch state and zone topology disclosed to unauthenticated actors on the LAN</title>
    <updated>2026-10-06T23:50:30.819264+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> home-assistant core</p>
<p>Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2026.6.0, the Konnected integration registers an HTTP endpoint, KonnectedView (homeassistant/components/konnected/__init__.py), that is marked as not requiring authentication (requires_auth = False). A comment next to that line says auth is instead handled "via the access token from configuration." That promise is only half true. Write requests (POST and PUT) are handled by update_sensor(), which does check the request's Authorization: Bearer &lt;token&gt; header against the integration's stored access tokens (using hmac.compare_digest). Read requests (GET) are handled by a separate get() method that has no authentication check at all. This vulnerability is fixed in 2026.6.0.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-54317"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-x84v-g949-293w</id>
    <title>GHSA-x84v-g949-293w — Home Assistant: Konnected alarm-panel switch state and zone topology disclosed to unauthenticated actors on the LAN</title>
    <updated>2026-10-06T23:50:30.819323+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: homeassistant</p>
<p>### Summary</p>
<p>The Konnected integration registers an HTTP endpoint, `KonnectedView` (`homeassistant/components/konnected/__init__.py`), that is marked as **not requiring authentication** (`requires_auth = False`). A comment next to that line says auth is instead handled "via the access token from configuration."</p>
<p>That promise is only half true:</p>
<p>- **Write requests (POST and PUT)** are handled by `update_sensor()`, which *does* check the request's `Authorization: Bearer &lt;token&gt;` header against the integration's stored access tokens (using `hmac.compare_digest`).
- **Read requests (GET)** are handled by a separate `get()` method that has **no authentication check at all.**</p>
<p>By sending GET requests to `/api/konnected/device/{device_id}?zone=N`, any unauthenticated client on the LAN can:</p>
<p>1. **Enumerate configured Konnected device IDs** — the endpoint returns a clean 404-vs-200 difference that acts as an oracle for which devices exist.
2. **Read switch output states** — the on/off state of every switch output (siren, strobe, and relay outputs of the alarm panel).
3. **Read the panel's zone topology** — how the alarm panel's zones are configured.
4. **Trigger panel connections** — each unauthenticated GET forces one outbound `panel.async_connect()` call to the Konnected hardware on the LAN.</p>
<p>The same URL that correctly rejects unauthenticated POST and PUT requests silently serves unauthenticated GET requests, leaking alarm-panel state and device topology to anyone who can reach Ho…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-x84v-g949-293w"/>
  </entry>
</feed>
