Inim Electronics Smartliving and SmartLAN Unauthenticated Server-Side Request Forgery Vulnerability

Vulnerability

A server-side request forgery (SSRF) vulnerability has been identified in Inim Electronics Smartliving SmartLAN/G/SI versions 6.x and prior. The vulnerability resides in the GetImage function, where the application fails to properly validate the 'host' parameter. This allows attackers to manipulate HTTP requests to external domains, potentially bypassing firewalls and conducting network enumeration through arbitrary HTTP requests via the onvif.cgi endpoint.

Impact

Exploitation of this vulnerability could lead to unauthorized network access and information exposure, allowing attackers to bypass firewalls and enumerate internal services and network resources.

Reproduction

The vulnerability can be reproduced by sending a POST request to the onvif.cgi endpoint with the 'mod' parameter set to 'GetImage' and the 'host' parameter pointing to an external domain. This will trigger the application to make an HTTP request to the specified domain, demonstrating the SSRF vulnerability.

Added: Jan 8, 2026, 12:24 AM
Updated: Jan 8, 2026, 12:24 AM

Vulnerability Rating

Custom Algorithm
spread
0.3
impact
7.5
exploitability
9.1
remediation
0.0
relevance
1.9
threat
6.4
urgency
2.9
incentive
10.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.