Homer 是一款开源的电信可观测性软件。在 11.0.283 版本之前,任何新部署的 Homer 系统若使用内部认证机制,其引导过程会自动创建一个名为 的管理员账户,密码为 (该密码以传统的 SHA-256 十六进制哈希形式存储)。系统未设置首次登录时强制修改密码的机制。因此,任何能够访问登录接口的攻击者均可立即获得完整的管理员权限。该漏洞已在版本 11.0.283 中修复。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| sipcapture | homer | < 11.0.283 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| sipcapture | homer | < 11.0.283 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-62253 | 9.8 CRITICAL | Homer: Complete Authentication Bypass When coordinator.jwt.secret Is Empty (Default) |
| CVE-2026-62251 | 8.1 HIGH | Homer: Authenticated SQL Injection via Unvalidated rawquery Field in /api/v4/statistics/qu |
No comments yet