eNet SMART HOME server 2.2.1 and 2.3.1 contains a privilege escalation vulnerability due to insufficient authorization checks in the setUserGroup JSON-RPC method. A low-privileged user (UG_USER) can send a crafted POST request to /jsonrpc/management specifying their own username to elevate their account to the UG_ADMIN group, bypassing intended access controls and gaining administrative capabilities such as modifying device configurations, network settings, and other smart home system functions.
An attacker logged in as a user in the UG_USER group sends a specially crafted HTTP POST request to the /jsonrpc/management endpoint, invoking the setUserGroup method and providing their own username and the target group UG_ADMIN as parameters. The server does not perform proper verification whether the caller has permissions to change the group membership of an account, so the change is accepted. As a result, the account is moved to the administrators group, bypassing the planned access control mechanisms.
The attacker gains full administrative privileges in the smart home system, allowing them to modify device configuration, network settings, and other system functions. This can lead to takeover of the entire intelligent building infrastructure.
Apply patches available from the vendor according to references. Until updates are applied, it is recommended to restrict access to the /jsonrpc/management endpoint exclusively to trusted IP addresses and to minimize the number of active user accounts in the system.
eNet SMART HOME Server in versions 2.2.1 and 2.3.1 by Jung-Group
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XJung Group Enet Smart Home
APPJung-Group2.2.12.3.1
Related vulnerabilities
Domyślne dane logowania w Jung-Group eNet SMART HOME Server
eNet SMART HOME server 2.2.1 and 2.3.1 contains a missing authorization vulnerability in the deleteUserAccount...
eNet SMART HOME server 2.2.1 and 2.3.1 contains a missing authorization vulnerability in the resetUserPassword...
JUNG Smart Visu Server 1.1.1050 contains a request header manipulation vulnerability that allows unauthenticat...
JUNG Smart Visu Server 1.1.1050 contains a denial of service vulnerability that allows unauthenticated attacke...