Title: MyDomoAtHome (MDAH) REST API Domoticz ISS Gateway 0.2.40 Information Disclosure Advisory ID: ZSL-2019-5555 Type: Local/Remote Impact: Exposure of System Information, Exposure of Sensitive Information, Security Bypass Risk: (4/5) Release Date: 29.12.2019 Summary REST Gateway between Domoticz and Imperihome ISS. Domoticz is a home automation system with a pretty wide library of supported devices, ranging from weather stations to smoke detectors to remote controls. Description MyDomoAtHome REST API is affected by an information disclosure vulnerability due to improper access control enforcement. Affected Version 0.2.40 Vendor Emmanuel - PoC domoticz_info.txt Credits Vulnerability discovered by Gjoko Krstic -