Critical MajorDoMo RCE (CVE-2026-27174): Unauthenticated Remote Code Execution Analysis
ID: dbfcd33d-f754-5928-b3e5-26472ce13e78
STIX ID: report--dbfcd33d-f754-5928-b3e5-26472ce13e78
Feed Name: Resecurity
CVE-2026-27174 is a critical unauthenticated remote code execution vulnerability in the MajorDoMo home-automation platform resulting from improper authentication handling (missing exit after redirect) combined with unsafe use of PHP eval(), allowing attackers to execute arbitrary PHP via the admin AJAX console; the report includes technical details, a public Nuclei detection template and curl PoC, impact analysis on IoT/home automation, and recommended mitigations such as restricting admin access, disabling the console, and applying vendor patches.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
