McCaulay

Vulnerability Research & Exploit Development

Month: October 2026

go2shell: Rooting Home Assistant through SSDP

7 October 20267 October 2026 McCaulayVulnerability Research

Home Assistant Green, a popular open-source home automation platform, was targeted at Pwn2Own Ireland 2025, resulting in a chain of vulnerabilities. I exploited an SSDP LOCATION SSRF to achieve unauthenticated remote code execution on the device. This vulnerability allowed the execution of commands by leveraging the go2rtc service.

Recent Posts

  • go2shell: Rooting Home Assistant through SSDP
  • RCEliteLLM – LiteLLM 1.83.14: Chaining an Environment Variable Leak with Jinja2 SSTI for Remote Code Execution
  • No Tokens Required: A Movie Power Virtual Reality Breakout Exploit
  • mast1c0re: Part 3 – Escaping the emulator
  • mast1c0re: Part 2 – Arbitrary PS2 code execution

Archives

  • October 2026
  • May 2026
  • July 2025
  • February 2023

Categories

  • Vulnerability Research
Copyright © All rights reserved.